<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Guess everyone makes mistakes</title>
	<atom:link href="http://www.sitepoint.com/blogs/2004/10/29/guess-everyone-makes-mistakes/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sitepoint.com/blogs/2004/10/29/guess-everyone-makes-mistakes/</link>
	<description>News, opinion, and fresh thinking for web developers and designers. The official podcast of sitepoint.com.</description>
	<pubDate>Tue, 02 Dec 2008 11:31:34 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: Ren</title>
		<link>http://www.sitepoint.com/blogs/2004/10/29/guess-everyone-makes-mistakes/#comment-1308</link>
		<dc:creator>Ren</dc:creator>
		<pubDate>Wed, 31 Dec 1969 19:00:00 +0000</pubDate>
		<guid isPermaLink="false">687593850#comment-1308</guid>
		<description>&lt;p&gt;Just wish there was mose support for HttpOnly cookies. (Both in non IE browsers, and PHP)&lt;/p&gt;

&lt;p&gt;http://msdn.microsoft.com/workshop/author/dhtml/httponly_cookies.asp&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>Just wish there was mose support for HttpOnly cookies. (Both in non IE browsers, and PHP)</p>
<p><a href="http://msdn.microsoft.com/workshop/author/dhtml/httponly_cookies.asp" rel="nofollow">http://msdn.microsoft.com/workshop/author/dhtml/httponly_cookies.asp</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: jon</title>
		<link>http://www.sitepoint.com/blogs/2004/10/29/guess-everyone-makes-mistakes/#comment-1309</link>
		<dc:creator>jon</dc:creator>
		<pubDate>Wed, 31 Dec 1969 19:00:00 +0000</pubDate>
		<guid isPermaLink="false">687593850#comment-1309</guid>
		<description>&lt;p&gt;Amen to that Ren. &lt;/p&gt;

&lt;p&gt;https://bugzilla.mozilla.org/show_bug.cgi?id=178993&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>Amen to that Ren. </p>
<p><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=178993" rel="nofollow">https://bugzilla.mozilla.org/show_bug.cgi?id=178993</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Shiflett</title>
		<link>http://www.sitepoint.com/blogs/2004/10/29/guess-everyone-makes-mistakes/#comment-1310</link>
		<dc:creator>Chris Shiflett</dc:creator>
		<pubDate>Wed, 31 Dec 1969 19:00:00 +0000</pubDate>
		<guid isPermaLink="false">687593850#comment-1310</guid>
		<description>&lt;p&gt;Thanks for the link, Harry. There's also a plain HTML version available on my Web site that some people might prefer:&lt;/p&gt;

&lt;p&gt;http://shiflett.org/articles/foiling-cross-site-attacks&lt;/p&gt;

&lt;p&gt;Do you have any details about the vulnerability? I know the original announcement was purposely vague, but I presume things have been fixed by now.&lt;/p&gt;

&lt;p&gt;Someone recently sent me a description of a supposed Gmail vulnerability, wanting me to determine whether their findings were valid. I was able to access their account, which was more than they had expected. However, the attack required me to access a URL that should only really be known by the user, and I never had a chance to look into it more. I think details about this recent attack might give me some more perspective about what Google is doing on the server side.&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>Thanks for the link, Harry. There&#8217;s also a plain HTML version available on my Web site that some people might prefer:</p>
<p><a href="http://shiflett.org/articles/foiling-cross-site-attacks" rel="nofollow">http://shiflett.org/articles/foiling-cross-site-attacks</a></p>
<p>Do you have any details about the vulnerability? I know the original announcement was purposely vague, but I presume things have been fixed by now.</p>
<p>Someone recently sent me a description of a supposed Gmail vulnerability, wanting me to determine whether their findings were valid. I was able to access their account, which was more than they had expected. However, the attack required me to access a URL that should only really be known by the user, and I never had a chance to look into it more. I think details about this recent attack might give me some more perspective about what Google is doing on the server side.</p>]]></content:encoded>
	</item>
</channel>
</rss>
