<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hacker&#039;s ad for a Yahoo email-stealing exploit, up for sale at&#160;$700</title>
	<atom:link href="http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Mon, 20 May 2013 14:16:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Hubert Figuière</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1591434</link>
		<dc:creator>Hubert Figuière</dc:creator>
		<pubDate>Mon, 26 Nov 2012 14:40:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1591434</guid>
		<description>Remember, Yahoo! Mail is still not offered over https. Which mean that it is already vulnerable to basic traffic sniffing.</description>
		<content:encoded><![CDATA[<p>Remember, Yahoo! Mail is still not offered over https. Which mean that it is already vulnerable to basic traffic sniffing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: R_Young</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1591218</link>
		<dc:creator>R_Young</dc:creator>
		<pubDate>Mon, 26 Nov 2012 00:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1591218</guid>
		<description>Perhaps you meant &quot;shouldn&#039;t&quot;.

The following question is then &quot;According to who?&quot;
or whom.  Whatever.</description>
		<content:encoded><![CDATA[<p>Perhaps you meant &#8220;shouldn&#8217;t&#8221;.</p>
<p>The following question is then &#8220;According to who?&#8221;<br />
or whom.  Whatever.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Boundegar</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1590745</link>
		<dc:creator>Boundegar</dc:creator>
		<pubDate>Sat, 24 Nov 2012 16:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1590745</guid>
		<description>Is that what they told you in Wired?</description>
		<content:encoded><![CDATA[<p>Is that what they told you in Wired?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: plyx</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1590722</link>
		<dc:creator>plyx</dc:creator>
		<pubDate>Sat, 24 Nov 2012 14:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1590722</guid>
		<description>Fuck this guy. Fuck all &quot;hackers&quot;. Real h4x0rz don&#039;t steal from common folk.</description>
		<content:encoded><![CDATA[<p>Fuck this guy. Fuck all &#8220;hackers&#8221;. Real h4x0rz don&#8217;t steal from common folk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tankut Erinc</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1590714</link>
		<dc:creator>Tankut Erinc</dc:creator>
		<pubDate>Sat, 24 Nov 2012 13:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1590714</guid>
		<description>it will be patched up as soon as yahoo puts together $700.  
oh wait! </description>
		<content:encoded><![CDATA[<p>it will be patched up as soon as yahoo puts together $700.<br />
oh wait! </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charlie B</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1590615</link>
		<dc:creator>Charlie B</dc:creator>
		<pubDate>Sat, 24 Nov 2012 04:33:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1590615</guid>
		<description>I&#039;m glad this stuff is out in the open.  If our corporate-owned governments had their way, we&#039;d never know about these vulnerabilities.</description>
		<content:encoded><![CDATA[<p>I&#8217;m glad this stuff is out in the open.  If our corporate-owned governments had their way, we&#8217;d never know about these vulnerabilities.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jake Rennie</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1590517</link>
		<dc:creator>Jake Rennie</dc:creator>
		<pubDate>Sat, 24 Nov 2012 00:40:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1590517</guid>
		<description>$700 for one exploit? I&#039;m in the wrong line of work.</description>
		<content:encoded><![CDATA[<p>$700 for one exploit? I&#8217;m in the wrong line of work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bklynchris</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1590505</link>
		<dc:creator>bklynchris</dc:creator>
		<pubDate>Sat, 24 Nov 2012 00:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1590505</guid>
		<description>...&quot;cause I don&#039;t want it to get patched soon!&quot; add dickweed to irony, and what a bizarrely written sentence.</description>
		<content:encoded><![CDATA[<p>&#8230;&#8221;cause I don&#8217;t want it to get patched soon!&#8221; add dickweed to irony, and what a bizarrely written sentence.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: invictus</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1590490</link>
		<dc:creator>invictus</dc:creator>
		<pubDate>Sat, 24 Nov 2012 00:02:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1590490</guid>
		<description>You&#039;re guessing incorrectly. Stored xss can execute on load, with no input from the user. It all depends on where in served page the script is being injected.
See http://en.wikipedia.org/wiki/Cross-site_scripting#Persistent for a brief explanation.</description>
		<content:encoded><![CDATA[<p>You&#8217;re guessing incorrectly. Stored xss can execute on load, with no input from the user. It all depends on where in served page the script is being injected.<br />
See <a href="http://en.wikipedia.org/wiki/Cross-site_scripting#Persistent" rel="nofollow">http://en.wikipedia.org/wiki/Cross-site_scripting#Persistent</a> for a brief explanation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: danimagoo</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1590482</link>
		<dc:creator>danimagoo</dc:creator>
		<pubDate>Fri, 23 Nov 2012 23:45:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1590482</guid>
		<description>&quot;Will sell only to trusted people&quot; ... irony much?</description>
		<content:encoded><![CDATA[<p>&#8220;Will sell only to trusted people&#8221; &#8230; irony much?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Glippiglop</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1590471</link>
		<dc:creator>Glippiglop</dc:creator>
		<pubDate>Fri, 23 Nov 2012 23:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1590471</guid>
		<description>Yes.  This is the sort of trick that you would use in a phishing expedition, whereby the attacker might only expect 1% of the 1,000,000 people he emailed to click on the link.  A career criminal could easily turn a profit from the initial investment.

It&#039;s a good trick to employ as the attacker does not need to forge the login page of the affected site; in fact the browser will likely log the user straight into the account if a cookie is active from a previous session.  This can be observed in the video.</description>
		<content:encoded><![CDATA[<p>Yes.  This is the sort of trick that you would use in a phishing expedition, whereby the attacker might only expect 1% of the 1,000,000 people he emailed to click on the link.  A career criminal could easily turn a profit from the initial investment.</p>
<p>It&#8217;s a good trick to employ as the attacker does not need to forge the login page of the affected site; in fact the browser will likely log the user straight into the account if a cookie is active from a previous session.  This can be observed in the video.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Buddy Bradley</title>
		<link>http://boingboing.net/2012/11/23/hackers-ad-for-a-yahoo-email.html#comment-1590439</link>
		<dc:creator>Buddy Bradley</dc:creator>
		<pubDate>Fri, 23 Nov 2012 22:38:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=195807#comment-1590439</guid>
		<description>I&#039;m guessing this only works if the victim is dumb enough to click on a link in a spammy-looking email, right? </description>
		<content:encoded><![CDATA[<p>I&#8217;m guessing this only works if the victim is dumb enough to click on a link in a spammy-looking email, right? </p>
]]></content:encoded>
	</item>
</channel>
</rss>
