<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Michele get&#8217;s hit by the Bloodhound exploit</title>
	<atom:link href="http://www.3nailsministries.org/2005/03/22/michele-gets-hit-by-the-bloodhound-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.3nailsministries.org/2005/03/22/michele-gets-hit-by-the-bloodhound-exploit/</link>
	<description>Walking the walk, sometimes crawling, often falling</description>
	<lastBuildDate>Thu, 10 Sep 2009 22:22:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: pilgrim</title>
		<link>http://www.3nailsministries.org/2005/03/22/michele-gets-hit-by-the-bloodhound-exploit/comment-page-1/#comment-706</link>
		<dc:creator>pilgrim</dc:creator>
		<pubDate>Sat, 26 Mar 2005 02:57:10 +0000</pubDate>
		<guid isPermaLink="false">http://3nailsministries.org/?p=84#comment-706</guid>
		<description>    See...this is what I get for not completing a post!  You are quite right that this is a SQL injection attack.  I&#039;m thinking that their was javascript injected into the her database that, once loaded, fired up the XSS attack bringing in the nasty stuff.

    I&#039;ve been looking around for the actual exploit code for the bloodhound bug with no joy.  I&#039;ll be moving this post to the top and finishing up the analysis soon.

    Thanks for the catch...you are dead on right.</description>
		<content:encoded><![CDATA[<p>See&#8230;this is what I get for not completing a post!  You are quite right that this is a SQL injection attack.  I&#8217;m thinking that their was javascript injected into the her database that, once loaded, fired up the XSS attack bringing in the nasty stuff.</p>
<p>    I&#8217;ve been looking around for the actual exploit code for the bloodhound bug with no joy.  I&#8217;ll be moving this post to the top and finishing up the analysis soon.</p>
<p>    Thanks for the catch&#8230;you are dead on right.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Knox</title>
		<link>http://www.3nailsministries.org/2005/03/22/michele-gets-hit-by-the-bloodhound-exploit/comment-page-1/#comment-645</link>
		<dc:creator>Knox</dc:creator>
		<pubDate>Wed, 23 Mar 2005 10:57:09 +0000</pubDate>
		<guid isPermaLink="false">http://3nailsministries.org/?p=84#comment-645</guid>
		<description>Hi,
  If I&#039;m understanding correctly, you&#039;re saying that ASV&#039;s virus was due to javascript being loaded into one of the comments.  Just putting a link wouldn&#039;t do it; it takes live javascript.  I do not know the mechanism for capturing comments, but it seems wrong for a site to allow live javascript to run because it got posted to a comment.  This seems similar to SQL injection attacks on websites, where insufficient screening of inputs allows malicious users to run their own queries against the database.  If other people&#039;s javascript can run on your site, it could potential rewrite portions of the screen, cause popup ads and a whole lot more, not just attempting to infect visitors with a virus.</description>
		<content:encoded><![CDATA[<p>Hi,<br />
  If I&#8217;m understanding correctly, you&#8217;re saying that ASV&#8217;s virus was due to javascript being loaded into one of the comments.  Just putting a link wouldn&#8217;t do it; it takes live javascript.  I do not know the mechanism for capturing comments, but it seems wrong for a site to allow live javascript to run because it got posted to a comment.  This seems similar to SQL injection attacks on websites, where insufficient screening of inputs allows malicious users to run their own queries against the database.  If other people&#8217;s javascript can run on your site, it could potential rewrite portions of the screen, cause popup ads and a whole lot more, not just attempting to infect visitors with a virus.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

