<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MustLive Edition" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Коментарі для запису: MoBiC-21: AIP CAPTCHA bypass</title>
	<link>http://websecurity.com.ua/1568/</link>
	<description></description>
	<pubDate>Tue, 07 Apr 2026 22:08:55 +0000</pubDate>
	<generator>http://wordpress.org/?v=MustLive Edition</generator>

	<item>
		<title>від: MustLive</title>
		<link>http://websecurity.com.ua/1568/#comment-119351</link>
		<pubDate>Thu, 03 Apr 2008 18:16:47 +0000</pubDate>
		<guid>http://websecurity.com.ua/1568/#comment-119351</guid>
					<description>&lt;strong&gt;Dave&lt;/strong&gt;

You are welcome.

&lt;blockquote&gt;I’ve recently deployed AIP 2.0, which fixes the vulnerability that you mentioned.&lt;/blockquote&gt;
It's good that you fixed this hole (in new version of AIP). If I'll find time I'll look at it ;-).</description>
		<content:encoded><![CDATA[<p><strong>Dave</strong></p>
<p>You are welcome.</p>
<blockquote><p>I’ve recently deployed AIP 2.0, which fixes the vulnerability that you mentioned.</p></blockquote>
<p>It&#8217;s good that you fixed this hole (in new version of AIP). If I&#8217;ll find time I&#8217;ll look at it <img src='http://websecurity.com.ua/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> .
</p>
]]></content:encoded>
				</item>
	<item>
		<title>від: Dave</title>
		<link>http://websecurity.com.ua/1568/#comment-119346</link>
		<pubDate>Thu, 03 Apr 2008 15:50:52 +0000</pubDate>
		<guid>http://websecurity.com.ua/1568/#comment-119346</guid>
					<description>I've recently deployed AIP 2.0, which fixes the vulnerability that you mentioned.

Thanks again for reporting it.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve recently deployed AIP 2.0, which fixes the vulnerability that you mentioned.</p>
<p>Thanks again for reporting it.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>від: Dave</title>
		<link>http://websecurity.com.ua/1568/#comment-86856</link>
		<pubDate>Thu, 13 Dec 2007 03:35:24 +0000</pubDate>
		<guid>http://websecurity.com.ua/1568/#comment-86856</guid>
					<description>I've posted info about my solution for AIP 2.0.0 in my blog: 

http://davesexton.com/blog/blogs/blog/archive/2007/12/12/aip-1-0-0-bypassed.aspx

Hopefully you'll find time to reevaluate AIP again and let me know if it passes all of your tests the second time around :)</description>
		<content:encoded><![CDATA[<p>I&#8217;ve posted info about my solution for AIP 2.0.0 in my blog: </p>
<p><a href="http://davesexton.com/blog/blogs/blog/archive/2007/12/12/aip-1-0-0-bypassed.aspx" rel="nofollow">http://davesexton.com/blog/blogs/blog/archive/2007/12/12/aip-1-0-0-bypassed.aspx</a></p>
<p>Hopefully you&#8217;ll find time to reevaluate AIP again and let me know if it passes all of your tests the second time around <img src='http://websecurity.com.ua/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
</p>
]]></content:encoded>
				</item>
	<item>
		<title>від: Dave</title>
		<link>http://websecurity.com.ua/1568/#comment-86764</link>
		<pubDate>Tue, 11 Dec 2007 23:28:24 +0000</pubDate>
		<guid>http://websecurity.com.ua/1568/#comment-86764</guid>
					<description>I certainly appreciate that you brought this to my attention.  It will be fixed in the next release.

However, the "Moral" that you stated isn't being fair to AIP.  "Unreliable" would indicate that it isn't working to protect web sites - its purpose.  Although there is certainly a potential risk that AIP could be bypassed, in my experience using AIP this has _never_ happened to me and you are the first to report it.  Hopefully, I'll be able to fix this bug before AIP actually does become "unreliable" :)

Thanks, 
- Dave</description>
		<content:encoded><![CDATA[<p>I certainly appreciate that you brought this to my attention.  It will be fixed in the next release.</p>
<p>However, the &#8220;Moral&#8221; that you stated isn&#8217;t being fair to AIP.  &#8220;Unreliable&#8221; would indicate that it isn&#8217;t working to protect web sites - its purpose.  Although there is certainly a potential risk that AIP could be bypassed, in my experience using AIP this has _never_ happened to me and you are the first to report it.  Hopefully, I&#8217;ll be able to fix this bug before AIP actually does become &#8220;unreliable&#8221; <img src='http://websecurity.com.ua/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Thanks,<br />
- Dave
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
