<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: BBpress XSS vulnerability</title>
	<link>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/</link>
	<description>Security Tools and Tips</description>
	<pubDate>Thu, 20 Nov 2008 16:01:16 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>

	<item>
		<title>By: Sam Bauers</title>
		<link>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/#comment-251</link>
		<author>Sam Bauers</author>
		<pubDate>Thu, 21 Jun 2007 01:52:54 +0000</pubDate>
		<guid>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/#comment-251</guid>
		<description>This has been fixed in version 0.8.2.1 of bbPress.

Back to zero vulnerabilities.</description>
		<content:encoded><![CDATA[<p>This has been fixed in version 0.8.2.1 of bbPress.</p>
<p>Back to zero vulnerabilities.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dragos Lungu</title>
		<link>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/#comment-132</link>
		<author>Dragos Lungu</author>
		<pubDate>Mon, 11 Jun 2007 13:03:23 +0000</pubDate>
		<guid>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/#comment-132</guid>
		<description>@Jordan
Yes, the referral check was the big show stopper for a 0 day announcement :)  
However, validating the $re variable takes only one line of code just like it's done with the user login : 
$user_login = user_sanitize ( @$_POST['user_login'] );</description>
		<content:encoded><![CDATA[<p>@Jordan<br />
Yes, the referral check was the big show stopper for a 0 day announcement <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
However, validating the $re variable takes only one line of code just like it&#8217;s done with the user login :<br />
$user_login = user_sanitize ( @$_POST[&#8217;user_login&#8217;] );</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/#comment-130</link>
		<author>Jordan</author>
		<pubDate>Mon, 11 Jun 2007 11:03:58 +0000</pubDate>
		<guid>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/#comment-130</guid>
		<description>Still, the fact that they are doing referer checking somewhat mitigates the attack.  Sure, there's a couple of hacks around it, but generally speaking it makes actually implementing this attack in the wild much more difficult than it would have otherwise.  Defense in depth, right?</description>
		<content:encoded><![CDATA[<p>Still, the fact that they are doing referer checking somewhat mitigates the attack.  Sure, there&#8217;s a couple of hacks around it, but generally speaking it makes actually implementing this attack in the wild much more difficult than it would have otherwise.  Defense in depth, right?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ory Segal</title>
		<link>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/#comment-119</link>
		<author>Ory Segal</author>
		<pubDate>Sun, 10 Jun 2007 11:58:58 +0000</pubDate>
		<guid>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/#comment-119</guid>
		<description>http://blog.watchfire.com/wfblog/2007/06/a_few_blurbs.html</description>
		<content:encoded><![CDATA[<p><a href="http://blog.watchfire.com/wfblog/2007/06/a_few_blurbs.html" rel="nofollow">http://blog.watchfire.com/wfblog/2007/06/a_few_blurbs.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Top 10 Open Source Forums - 12 Months of Vulnerabilities &#124; Dragos Lungu Dot Com</title>
		<link>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/#comment-97</link>
		<author>Top 10 Open Source Forums - 12 Months of Vulnerabilities &#124; Dragos Lungu Dot Com</author>
		<pubDate>Thu, 07 Jun 2007 11:06:24 +0000</pubDate>
		<guid>http://www.dragoslungu.com/2007/06/07/bbpress-xss-vulnerability/#comment-97</guid>
		<description>[...] : BBpress XSS Vulnerability Beehive : [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] : BBpress XSS Vulnerability Beehive : [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
