<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: The Digg worm that wasn&#8217;t</title>
	<atom:link href="http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/feed/" rel="self" type="application/rss+xml" />
	<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/</link>
	<description>PHP, Symfony, JavaScript, jQuery, MooTools consultant.</description>
	<pubDate>Tue, 16 Mar 2010 09:14:49 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Quick Find Tech News &#187; Security Expert Suggests Twitter Focus on Output Escaping not Input Filtering</title>
		<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/comment-page-1/#comment-4027</link>
		<dc:creator>Quick Find Tech News &#187; Security Expert Suggests Twitter Focus on Output Escaping not Input Filtering</dc:creator>
		<pubDate>Mon, 20 Apr 2009 16:04:45 +0000</pubDate>
		<guid isPermaLink="false">http://devthought.com/?p=827#comment-4027</guid>
		<description>[...] However, Twitter is not alone in this. Guillermo Rauch found a similar vulnerability in Digg today that he tested and quickly alerted Digg to (Digg has since fixed the bug). You can read about the process here. [...]</description>
		<content:encoded><![CDATA[<p>[...] However, Twitter is not alone in this. Guillermo Rauch found a similar vulnerability in Digg today that he tested and quickly alerted Digg to (Digg has since fixed the bug). You can read about the process here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DionD (Dion DiFelice)</title>
		<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/comment-page-1/#comment-4186</link>
		<dc:creator>DionD (Dion DiFelice)</dc:creator>
		<pubDate>Sun, 19 Apr 2009 21:10:05 +0000</pubDate>
		<guid isPermaLink="false">http://devthought.com/?p=827#comment-4186</guid>
		<description>Small lesson on #XSS and those nasty little #worms that keep making #Digg and #Twitter sick!  http://bit.ly/UTovP  #fail #notfun</description>
		<content:encoded><![CDATA[<p>Small lesson on #XSS and those nasty little #worms that keep making #Digg and #Twitter sick!  <a href="http://bit.ly/UTovP" rel="nofollow">http://bit.ly/UTovP</a>  #fail #notfun</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AllenHarkleroad (AllenHarkleroad)</title>
		<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/comment-page-1/#comment-4180</link>
		<dc:creator>AllenHarkleroad (AllenHarkleroad)</dc:creator>
		<pubDate>Sun, 19 Apr 2009 15:17:28 +0000</pubDate>
		<guid isPermaLink="false">http://devthought.com/?p=827#comment-4180</guid>
		<description>The Digg worm that wasn’t (Devthought) http://tinyurl.com/c4czdz</description>
		<content:encoded><![CDATA[<p>The Digg worm that wasn’t (Devthought) <a href="http://tinyurl.com/c4czdz" rel="nofollow">http://tinyurl.com/c4czdz</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alzaid (Saleh Alzaid)</title>
		<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/comment-page-1/#comment-4181</link>
		<dc:creator>alzaid (Saleh Alzaid)</dc:creator>
		<pubDate>Sun, 19 Apr 2009 07:47:50 +0000</pubDate>
		<guid isPermaLink="false">http://devthought.com/?p=827#comment-4181</guid>
		<description>The blog has a pretty design too :) try to drag and drop the clouds :) RT: &lt;a rel="nofollow" href="http://twitter.com/anaimi"&gt;@anaimi&lt;/a&gt;: XSS on Digg ... http://tinyurl.com/c4czdz</description>
		<content:encoded><![CDATA[<p>The blog has a pretty design too <img src='http://devthought.com/wp-content/plugins/smilies-themer/devthought/smile.png' alt=':)' class='wp-smiley' /> try to drag and drop the clouds <img src='http://devthought.com/wp-content/plugins/smilies-themer/devthought/smile.png' alt=':)' class='wp-smiley' /> RT: <a rel="nofollow" href="http://twitter.com/anaimi">@anaimi</a>: XSS on Digg &#8230; <a href="http://tinyurl.com/c4czdz" rel="nofollow">http://tinyurl.com/c4czdz</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anaimi (anaimi)</title>
		<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/comment-page-1/#comment-4182</link>
		<dc:creator>anaimi (anaimi)</dc:creator>
		<pubDate>Sun, 19 Apr 2009 07:35:10 +0000</pubDate>
		<guid isPermaLink="false">http://devthought.com/?p=827#comment-4182</guid>
		<description>XSS on Digg ... http://tinyurl.com/c4czdz</description>
		<content:encoded><![CDATA[<p>XSS on Digg &#8230; <a href="http://tinyurl.com/c4czdz" rel="nofollow">http://tinyurl.com/c4czdz</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guillermo Rauch</title>
		<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/comment-page-1/#comment-3996</link>
		<dc:creator>Guillermo Rauch</dc:creator>
		<pubDate>Sun, 19 Apr 2009 06:39:30 +0000</pubDate>
		<guid isPermaLink="false">http://devthought.com/?p=827#comment-3996</guid>
		<description>Apparently it should be the same, given 

&lt;code class="inline"&gt;$config['global_xss_filtering'] = TRUE;&lt;/code&gt;

is enabled.</description>
		<content:encoded><![CDATA[<p>Apparently it should be the same, given </p>
<p><code class="inline">$config['global_xss_filtering'] = TRUE;</code></p>
<p>is enabled.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: two_way_web (Two Way Web)</title>
		<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/comment-page-1/#comment-4183</link>
		<dc:creator>two_way_web (Two Way Web)</dc:creator>
		<pubDate>Sun, 19 Apr 2009 04:39:20 +0000</pubDate>
		<guid isPermaLink="false">http://devthought.com/?p=827#comment-4183</guid>
		<description>RT &lt;a rel="nofollow" href="http://twitter.com/stejules"&gt;@stejules&lt;/a&gt; The Digg worm that wasn't http://tinyurl.com/c4czdz also C Did Digg Just Dodge a Mikeyy Worm?  http://tinyurl.com/d3lzyl</description>
		<content:encoded><![CDATA[<p>RT <a rel="nofollow" href="http://twitter.com/stejules">@stejules</a> The Digg worm that wasn&#8217;t <a href="http://tinyurl.com/c4czdz" rel="nofollow">http://tinyurl.com/c4czdz</a> also C Did Digg Just Dodge a Mikeyy Worm?  <a href="http://tinyurl.com/d3lzyl" rel="nofollow">http://tinyurl.com/d3lzyl</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stejules (stejules)</title>
		<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/comment-page-1/#comment-4184</link>
		<dc:creator>stejules (stejules)</dc:creator>
		<pubDate>Sun, 19 Apr 2009 04:38:03 +0000</pubDate>
		<guid isPermaLink="false">http://devthought.com/?p=827#comment-4184</guid>
		<description>The Digg worm that wasn't http://tinyurl.com/c4czdz also C Did Digg Just Dodge a Mikeyy Worm?  http://tinyurl.com/d3lzyl</description>
		<content:encoded><![CDATA[<p>The Digg worm that wasn&#8217;t <a href="http://tinyurl.com/c4czdz" rel="nofollow">http://tinyurl.com/c4czdz</a> also C Did Digg Just Dodge a Mikeyy Worm?  <a href="http://tinyurl.com/d3lzyl" rel="nofollow">http://tinyurl.com/d3lzyl</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claude</title>
		<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/comment-page-1/#comment-3993</link>
		<dc:creator>Claude</dc:creator>
		<pubDate>Sun, 19 Apr 2009 04:33:03 +0000</pubDate>
		<guid isPermaLink="false">http://devthought.com/?p=827#comment-3993</guid>
		<description>Nice job Guillermo.

You mentioned that the Symfony framework does a good job of sanitizing input to avoid XSS exploits. Have you tried &lt;a href="http://codeigniter.com/user_guide/libraries/input.html" rel="nofollow"&gt;CodeIgniter's XSS filtering&lt;/a&gt;, and if so, what's your take on it?

Thanks.</description>
		<content:encoded><![CDATA[<p>Nice job Guillermo.</p>
<p>You mentioned that the Symfony framework does a good job of sanitizing input to avoid XSS exploits. Have you tried <a href="http://codeigniter.com/user_guide/libraries/input.html" rel="nofollow">CodeIgniter&#8217;s XSS filtering</a>, and if so, what&#8217;s your take on it?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mmaunder (Mark Maunder)</title>
		<link>http://devthought.com/blog/server-side/2009/04/the-digg-worm-that-wasnt/comment-page-1/#comment-4185</link>
		<dc:creator>mmaunder (Mark Maunder)</dc:creator>
		<pubDate>Sun, 19 Apr 2009 03:51:47 +0000</pubDate>
		<guid isPermaLink="false">http://devthought.com/?p=827#comment-4185</guid>
		<description>Simple XSS exploit for Digg (now fixed) http://tinyurl.com/c4czdz</description>
		<content:encoded><![CDATA[<p>Simple XSS exploit for Digg (now fixed) <a href="http://tinyurl.com/c4czdz" rel="nofollow">http://tinyurl.com/c4czdz</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
