<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to Steal DreamHost accounts?</title>
	<atom:link href="http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/feed/" rel="self" type="application/rss+xml" />
	<link>http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/</link>
	<description>Guy Mizrahi about Security and Technology.</description>
	<lastBuildDate>Sun, 01 Aug 2010 17:25:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: ___the</title>
		<link>http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/comment-page-1/#comment-13</link>
		<dc:creator>___the</dc:creator>
		<pubDate>Wed, 09 Jul 2008 22:20:47 +0000</pubDate>
		<guid isPermaLink="false">http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/#comment-13</guid>
		<description>i think that csrf is very easy to secure one way is to create a security_token
and this is the best secure form csrf...</description>
		<content:encoded><![CDATA[<p>i think that csrf is very easy to secure one way is to create a security_token<br />
and this is the best secure form csrf&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guy Mizrahi</title>
		<link>http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/comment-page-1/#comment-12</link>
		<dc:creator>Guy Mizrahi</dc:creator>
		<pubDate>Tue, 08 Jul 2008 10:24:32 +0000</pubDate>
		<guid isPermaLink="false">http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/#comment-12</guid>
		<description>I think you are all missing the point here.
It is obvious you can secure this operation (change details) in many different ways.
The point is that DreamHost didn&#039;t think that there is a need to secure it.
That is whats bothering me.</description>
		<content:encoded><![CDATA[<p>I think you are all missing the point here.<br />
It is obvious you can secure this operation (change details) in many different ways.<br />
The point is that DreamHost didn&#8217;t think that there is a need to secure it.<br />
That is whats bothering me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mark</title>
		<link>http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/comment-page-1/#comment-11</link>
		<dc:creator>mark</dc:creator>
		<pubDate>Sun, 06 Jul 2008 12:13:09 +0000</pubDate>
		<guid isPermaLink="false">http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/#comment-11</guid>
		<description>you can also add some small text box with random password that the user need to fill.</description>
		<content:encoded><![CDATA[<p>you can also add some small text box with random password that the user need to fill.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cp77fk4r</title>
		<link>http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/comment-page-1/#comment-10</link>
		<dc:creator>cp77fk4r</dc:creator>
		<pubDate>Fri, 04 Jul 2008 11:26:43 +0000</pubDate>
		<guid isPermaLink="false">http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/#comment-10</guid>
		<description>L[s]D - it&#039;s not so difficult to secure that. you just need to make sure that all the user that want to make a new changes his account must type his password in the form...</description>
		<content:encoded><![CDATA[<p>L[s]D &#8211; it&#8217;s not so difficult to secure that. you just need to make sure that all the user that want to make a new changes his account must type his password in the form&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: L[s]D</title>
		<link>http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/comment-page-1/#comment-7</link>
		<dc:creator>L[s]D</dc:creator>
		<pubDate>Tue, 17 Jun 2008 08:20:48 +0000</pubDate>
		<guid isPermaLink="false">http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/#comment-7</guid>
		<description>well, this method isn&#039;t new.. 
it is called XSRF (cross site request forgery).
I really like this sec hole cuz almost every site has it, it is very difficult to secure.</description>
		<content:encoded><![CDATA[<p>well, this method isn&#8217;t new..<br />
it is called XSRF (cross site request forgery).<br />
I really like this sec hole cuz almost every site has it, it is very difficult to secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: איך פורצים לחשבון HOSTING של DREAMHOST? &#124; ZuLL, יומנו של האקר.</title>
		<link>http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/comment-page-1/#comment-6</link>
		<dc:creator>איך פורצים לחשבון HOSTING של DREAMHOST? &#124; ZuLL, יומנו של האקר.</dc:creator>
		<pubDate>Tue, 17 Jun 2008 03:29:43 +0000</pubDate>
		<guid isPermaLink="false">http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts/#comment-6</guid>
		<description>[...] http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts" rel="nofollow">http://guymizrahi.com/2008/06/14/how-to-steal-dreamhost-accounts</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

