<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MustLive Edition" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Коментарі для запису: Уразливість на ebay.com</title>
	<link>http://websecurity.com.ua/2348/</link>
	<description></description>
	<pubDate>Mon, 20 Apr 2026 09:17:06 +0000</pubDate>
	<generator>http://wordpress.org/?v=MustLive Edition</generator>

	<item>
		<title>від: MustLive</title>
		<link>http://websecurity.com.ua/2348/#comment-265805</link>
		<pubDate>Sun, 22 Feb 2009 21:55:05 +0000</pubDate>
		<guid>http://websecurity.com.ua/2348/#comment-265805</guid>
					<description>&lt;strong&gt;Jackson&lt;/strong&gt;

Thank's for information. Encoded with base64 XSS code also belongs to this type of XSS which I called Encrypted XSS. All encrypted (with any ecryption) XSS holes belong to it. In this case, as you see, it's not base64, but eBay's own encryption algorithm.

Yes, this type of XSS can be used to bypass server-side and client-side firewalls, which block XSS attacks, like NoScript.

Hole at Yahoo! is nice. It's not first base64 encrypted XSS - there was such one at MySpace, which was disclosed in 2007 in project &lt;a href="/878/" rel="nofollow"&gt;Month of MySpace Bugs&lt;/a&gt;. But only after I found this XSS at eBay in 26.11.2007, I created this new type of XSS (as a part of my Classification of Cross-Site Scripting). And so I called this hole first Encrypted XSS (and it's first with such encryption).</description>
		<content:encoded><![CDATA[<p><strong>Jackson</strong></p>
<p>Thank&#8217;s for information. Encoded with base64 XSS code also belongs to this type of XSS which I called Encrypted XSS. All encrypted (with any ecryption) XSS holes belong to it. In this case, as you see, it&#8217;s not base64, but eBay&#8217;s own encryption algorithm.</p>
<p>Yes, this type of XSS can be used to bypass server-side and client-side firewalls, which block XSS attacks, like NoScript.</p>
<p>Hole at Yahoo! is nice. It&#8217;s not first base64 encrypted XSS - there was such one at MySpace, which was disclosed in 2007 in project <a href="/878/" rel="nofollow">Month of MySpace Bugs</a>. But only after I found this XSS at eBay in 26.11.2007, I created this new type of XSS (as a part of my Classification of Cross-Site Scripting). And so I called this hole first Encrypted XSS (and it&#8217;s first with such encryption).
</p>
]]></content:encoded>
				</item>
	<item>
		<title>від: Jackson</title>
		<link>http://websecurity.com.ua/2348/#comment-264706</link>
		<pubDate>Wed, 18 Feb 2009 04:07:00 +0000</pubDate>
		<guid>http://websecurity.com.ua/2348/#comment-264706</guid>
					<description>Hi MustLive!

Yahoo! (at least) once got this kind of encoded XSS. 

http://bbs.cn.yahoo.com/searchApplyBoard/PHNjcmlwdD5hbGVydCgiWFNTLWJ5cGFzcy1Oby1TY3JpcHQiKTwvc2NyaXB0Pg==.html

The XSS is encoded with base64(). This XSS was once bypassed No-Script protection too :D

You can see Maone's comment here :

http://zoiz.web.id/xss-corner/base64-encoded-xss.html</description>
		<content:encoded><![CDATA[<p>Hi MustLive!</p>
<p>Yahoo! (at least) once got this kind of encoded XSS. </p>
<p><a href="http://bbs.cn.yahoo.com/searchApplyBoard/PHNjcmlwdD5hbGVydCgiWFNTLWJ5cGFzcy1Oby1TY3JpcHQiKTwvc2NyaXB0Pg==.html" rel="nofollow">http://bbs.cn.yahoo.com/searchApplyBoard/PHNjcmlwdD5hbGVydCgiWFNTLWJ5cGFzcy1Oby1TY3JpcHQiKTwvc2NyaXB0Pg==.html</a></p>
<p>The XSS is encoded with base64(). This XSS was once bypassed No-Script protection too <img src='http://websecurity.com.ua/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>You can see Maone&#8217;s comment here :</p>
<p><a href="http://zoiz.web.id/xss-corner/base64-encoded-xss.html" rel="nofollow">http://zoiz.web.id/xss-corner/base64-encoded-xss.html</a>
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
