<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MustLive Edition" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Коментарі для запису: MoBiC-26 Bonus: XSS in Captcha!</title>
	<link>http://websecurity.com.ua/1588/</link>
	<description></description>
	<pubDate>Mon, 06 Apr 2026 05:17:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=MustLive Edition</generator>

	<item>
		<title>від: Boriel</title>
		<link>http://websecurity.com.ua/1588/#comment-87855</link>
		<pubDate>Sat, 22 Dec 2007 22:21:40 +0000</pubDate>
		<guid>http://websecurity.com.ua/1588/#comment-87855</guid>
					<description>Don't know why, but Firefox Warning is no longer appearing. :?: so users better install NoScript! extension. 

Regarding your Captcha, it is very unsecure, since it allows OCR attack (chars are easily recognisable by a program).</description>
		<content:encoded><![CDATA[<p>Don&#8217;t know why, but Firefox Warning is no longer appearing. <img src='http://websecurity.com.ua/wp-includes/images/smilies/icon_confused.gif' alt=':?' class='wp-smiley' /> : so users better install NoScript! extension. </p>
<p>Regarding your Captcha, it is very unsecure, since it allows OCR attack (chars are easily recognisable by a program).
</p>
]]></content:encoded>
				</item>
	<item>
		<title>від: Boriel</title>
		<link>http://websecurity.com.ua/1588/#comment-87840</link>
		<pubDate>Sat, 22 Dec 2007 21:54:18 +0000</pubDate>
		<guid>http://websecurity.com.ua/1588/#comment-87840</guid>
					<description>Hi! As said here: http://www.boriel.com/2006/05/27/bye-bye-captcha/ Captcha! is bit unmaintaned (I will fix this today, anyway). This hack won't work for Firefox (at less on 2.0.0.11) users, as javascript submits will display a warning message and an "Ok" button. But maybe in IE, they will do. :!:</description>
		<content:encoded><![CDATA[<p>Hi! As said here: <a href="http://www.boriel.com/2006/05/27/bye-bye-captcha/" rel="nofollow">http://www.boriel.com/2006/05/27/bye-bye-captcha/</a> Captcha! is bit unmaintaned (I will fix this today, anyway). This hack won&#8217;t work for Firefox (at less on 2.0.0.11) users, as javascript submits will display a warning message and an &#8220;Ok&#8221; button. But maybe in IE, they will do.  <img src='http://websecurity.com.ua/wp-includes/images/smilies/icon_exclaim.gif' alt=':!:' class='wp-smiley' />
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
