<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7187638509715645910</id><updated>2012-02-16T04:26:49.986-08:00</updated><title type='text'>Script 2 Root</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://xss2root.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7187638509715645910/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://xss2root.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Script Hacker</name><uri>http://www.blogger.com/profile/15223820577941348147</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7187638509715645910.post-7472261145323312193</id><published>2007-11-06T02:08:00.000-08:00</published><updated>2007-11-06T02:23:02.528-08:00</updated><title type='text'>A gmail 0day</title><content type='html'>There is a xss in &lt;a href="https://www.google.com/"&gt;https://www.google.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Poc:http://www.loveshell.net/blog/blogview.asp?logID=262&lt;br /&gt;&lt;br /&gt;This xss is very critical,you can get the cookie to login into gmail ore other service.&lt;br /&gt;&lt;br /&gt;The document.location.hash is evil :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7187638509715645910-7472261145323312193?l=xss2root.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://xss2root.blogspot.com/feeds/7472261145323312193/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7187638509715645910&amp;postID=7472261145323312193' title='1 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7187638509715645910/posts/default/7472261145323312193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7187638509715645910/posts/default/7472261145323312193'/><link rel='alternate' type='text/html' href='http://xss2root.blogspot.com/2007/11/gmail-0day.html' title='A gmail 0day'/><author><name>Script Hacker</name><uri>http://www.blogger.com/profile/15223820577941348147</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
