<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>

<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/Own-thenet-WebApplicationSecurityAndSeo" type="application/rss+xml" /><item><title>Use any free PHP hosting as an ultra-fast HTTP proxy</title><description>If you're not a US resident, you know how annoying the Internet can be sometimes. All those "US only" sites really manage to get under my skin. Especially when it's the really good ones that block access, like Pandora or Hulu, for example.

T ...</description><link>http://feedproxy.google.com/~r/Own-thenet-WebApplicationSecurityAndSeo/~3/Zf0dOnM3n6A/news_Use-any-free-PHP-hosting-as-an-ultra-fast-HTTP-proxy_24.html</link><feedburner:origLink>http://own-the.net/news_Use-any-free-PHP-hosting-as-an-ultra-fast-HTTP-proxy_24.html</feedburner:origLink></item><item><title>Problems with DNS rebinding demo</title><description>It's my fault this thing won't work on IE as planned.
 
Apparently, IE doesn't allow "third party cookies" by default. For instance, cookies that are set by an image that is hosted on another domain.

So if I put the following c ...</description><link>http://feedproxy.google.com/~r/Own-thenet-WebApplicationSecurityAndSeo/~3/ObAIfZuLaEs/news_Problems-with-DNS-rebinding-demo_23.html</link><feedburner:origLink>http://own-the.net/news_Problems-with-DNS-rebinding-demo_23.html</feedburner:origLink></item><item><title>DNS Rebinding PoC</title><description>It took me longer than I expected, but I finally made it work.

In short, this proof of concept uses the browser cache along with DNS Rebinding in order to circumvent the Same Origin Policy of the XMLHttpRequest object. After a successful exe ...</description><link>http://feedproxy.google.com/~r/Own-thenet-WebApplicationSecurityAndSeo/~3/4lOZ6FH4pUw/news_DNS-Rebinding-PoC_22.html</link><feedburner:origLink>http://own-the.net/news_DNS-Rebinding-PoC_22.html</feedburner:origLink></item><item><title>DNS Rebinding (or what's left of it)</title><description>DNS rebinding has been a widely known issue since 1996. 12 years later, the attack is still alive.

I've spent quite some time researching what's still left of the attack, and did find out that most known vectors were patched or mitigated by  ...</description><link>http://feedproxy.google.com/~r/Own-thenet-WebApplicationSecurityAndSeo/~3/Qtg0nP20Gq4/news_DNS-Rebinding-or-what039s-left-of-it_21.html</link><feedburner:origLink>http://own-the.net/news_DNS-Rebinding-or-what039s-left-of-it_21.html</feedburner:origLink></item><item><title>Digg.com transparent iframe CSRF PoC</title><description>As I promised here yesterday, here is your working PoC:

A page that diggs itself
Or a ...</description><link>http://feedproxy.google.com/~r/Own-thenet-WebApplicationSecurityAndSeo/~3/7vZ1qTADa70/news_Diggcom-transparent-iframe-CSRF-PoC_20.html</link><feedburner:origLink>http://own-the.net/news_Diggcom-transparent-iframe-CSRF-PoC_20.html</feedburner:origLink></item><title>Own-the.net - Web application security and SEO</title>
<description>A blog about findings in web application security, search engine oprimization and everything in between.</description>
<link>http://own-the.net</link>
</channel>
</rss>
