<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Apple.com XSS Exploit found on iTunes site</title>
	<atom:link href="http://osxdaily.com/2009/11/03/apple-com-xss-exploit-found-on-itunes-site/feed/" rel="self" type="application/rss+xml" />
	<link>http://osxdaily.com/2009/11/03/apple-com-xss-exploit-found-on-itunes-site/</link>
	<description>News, tips, software, reviews, and more for Mac OS X, iPhone, iPad</description>
	<lastBuildDate>Sun, 12 Feb 2012 23:11:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<item>
		<title>By: XSS Exploit found on Apple iTunes site&#8230; again - OS X Daily</title>
		<link>http://osxdaily.com/2009/11/03/apple-com-xss-exploit-found-on-itunes-site/#comment-98210</link>
		<dc:creator>XSS Exploit found on Apple iTunes site&#8230; again - OS X Daily</dc:creator>
		<pubDate>Wed, 18 Nov 2009 20:17:03 +0000</pubDate>
		<guid isPermaLink="false">http://osxdaily.com/?p=1770#comment-98210</guid>
		<description>[...] few weeks ago, there was an active XSS Exploit on Apple.com with their iTunes site. Well, a tipster sent us the exact same cross site scripting exploit that [...]</description>
		<content:encoded><![CDATA[<p>[...] few weeks ago, there was an active XSS Exploit on Apple.com with their iTunes site. Well, a tipster sent us the exact same cross site scripting exploit that [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Apple-Overload! &#187; Apple&#8217;s iTunes Affiliates site briefly subjected to image swaps</title>
		<link>http://osxdaily.com/2009/11/03/apple-com-xss-exploit-found-on-itunes-site/#comment-97692</link>
		<dc:creator>Apple-Overload! &#187; Apple&#8217;s iTunes Affiliates site briefly subjected to image swaps</dc:creator>
		<pubDate>Wed, 04 Nov 2009 11:06:03 +0000</pubDate>
		<guid isPermaLink="false">http://osxdaily.com/?p=1770#comment-97692</guid>
		<description>[...] friends over at OS X Daily passed along their story noting that Apple&#8217;s site for iTunes Affiliates was vulnerable to a [...]</description>
		<content:encoded><![CDATA[<p>[...] friends over at OS X Daily passed along their story noting that Apple&#8217;s site for iTunes Affiliates was vulnerable to a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Apple&#8217;s iTunes Affiliates site briefly subjected to image swaps &#171;</title>
		<link>http://osxdaily.com/2009/11/03/apple-com-xss-exploit-found-on-itunes-site/#comment-97691</link>
		<dc:creator>Apple&#8217;s iTunes Affiliates site briefly subjected to image swaps &#171;</dc:creator>
		<pubDate>Wed, 04 Nov 2009 10:33:07 +0000</pubDate>
		<guid isPermaLink="false">http://osxdaily.com/?p=1770#comment-97691</guid>
		<description>[...] friends over at OS X Daily passed along their story noting that Apple&#8217;s site for iTunes Affiliates was vulnerable to a [...]</description>
		<content:encoded><![CDATA[<p>[...] friends over at OS X Daily passed along their story noting that Apple&#8217;s site for iTunes Affiliates was vulnerable to a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Apple&#8217;s iTunes Affiliates site briefly subjected to image swaps&#160;&#124;&#160;Design City</title>
		<link>http://osxdaily.com/2009/11/03/apple-com-xss-exploit-found-on-itunes-site/#comment-97683</link>
		<dc:creator>Apple&#8217;s iTunes Affiliates site briefly subjected to image swaps&#160;&#124;&#160;Design City</dc:creator>
		<pubDate>Wed, 04 Nov 2009 05:15:13 +0000</pubDate>
		<guid isPermaLink="false">http://osxdaily.com/?p=1770#comment-97683</guid>
		<description>[...] under: Hacks, iTunes, AppleOur friends over at OS X Daily passed along their story noting that Apple&#8217;s site for iTunes Affiliates was vulnerable to a [...]</description>
		<content:encoded><![CDATA[<p>[...] under: Hacks, iTunes, AppleOur friends over at OS X Daily passed along their story noting that Apple&#8217;s site for iTunes Affiliates was vulnerable to a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Apple&#8217;s iTunes Affiliates site briefly subjected to image swaps &#124; Tech Stories, Games and Gadgets - BackLINK</title>
		<link>http://osxdaily.com/2009/11/03/apple-com-xss-exploit-found-on-itunes-site/#comment-97679</link>
		<dc:creator>Apple&#8217;s iTunes Affiliates site briefly subjected to image swaps &#124; Tech Stories, Games and Gadgets - BackLINK</dc:creator>
		<pubDate>Wed, 04 Nov 2009 03:11:35 +0000</pubDate>
		<guid isPermaLink="false">http://osxdaily.com/?p=1770#comment-97679</guid>
		<description>[...] friends over at OS X Daily passed along their story noting that Apple&#8217;s site for iTunes Affiliates was vulnerable to a [...]</description>
		<content:encoded><![CDATA[<p>[...] friends over at OS X Daily passed along their story noting that Apple&#8217;s site for iTunes Affiliates was vulnerable to a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Billy</title>
		<link>http://osxdaily.com/2009/11/03/apple-com-xss-exploit-found-on-itunes-site/#comment-97666</link>
		<dc:creator>Billy</dc:creator>
		<pubDate>Wed, 04 Nov 2009 01:09:56 +0000</pubDate>
		<guid isPermaLink="false">http://osxdaily.com/?p=1770#comment-97666</guid>
		<description>It is a true XSS exploit.

http://en.wikipedia.org/wiki/Cross-site_scripting</description>
		<content:encoded><![CDATA[<p>It is a true XSS exploit.</p>
<p><a href="http://en.wikipedia.org/wiki/Cross-site_scripting" rel="nofollow">http://en.wikipedia.org/wiki/Cross-site_scripting</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Update RSS &#187; Apple&#8217;s iTunes Affiliates site briefly subjected to image swaps</title>
		<link>http://osxdaily.com/2009/11/03/apple-com-xss-exploit-found-on-itunes-site/#comment-97665</link>
		<dc:creator>Update RSS &#187; Apple&#8217;s iTunes Affiliates site briefly subjected to image swaps</dc:creator>
		<pubDate>Wed, 04 Nov 2009 01:08:55 +0000</pubDate>
		<guid isPermaLink="false">http://osxdaily.com/?p=1770#comment-97665</guid>
		<description>[...] friends over at OS X Daily passed along their story noting that Apple&#8217;s site for iTunes Affiliates was vulnerable to a [...]</description>
		<content:encoded><![CDATA[<p>[...] friends over at OS X Daily passed along their story noting that Apple&#8217;s site for iTunes Affiliates was vulnerable to a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HolyMoly</title>
		<link>http://osxdaily.com/2009/11/03/apple-com-xss-exploit-found-on-itunes-site/#comment-97661</link>
		<dc:creator>HolyMoly</dc:creator>
		<pubDate>Tue, 03 Nov 2009 23:49:44 +0000</pubDate>
		<guid isPermaLink="false">http://osxdaily.com/?p=1770#comment-97661</guid>
		<description>I don&#039;t think this is true XSS Exploit because it is sanitized, however I was able to force multiple downloads without confirmation to several machines by inserting an iframe with a direct download link, that is just too easy. I can also replicate the endless popups you described and you have to kill the browser to escape the loop.

Someone is getting fired!</description>
		<content:encoded><![CDATA[<p>I don&#8217;t think this is true XSS Exploit because it is sanitized, however I was able to force multiple downloads without confirmation to several machines by inserting an iframe with a direct download link, that is just too easy. I can also replicate the endless popups you described and you have to kill the browser to escape the loop.</p>
<p>Someone is getting fired!</p>
]]></content:encoded>
	</item>
</channel>
</rss>


<!-- W3 Total Cache: Page cache debug info:
Engine:             disk (enhanced)
Key:                2009/11/03/apple-com-xss-exploit-found-on-itunes-site/feed/_index.html
Caching:            disabled
Reject reason:      user agent is rejected
Status:             not cached
Creation Time:      0.098s
Header info:
X-Pingback:         http://osxdaily.com/xmlrpc.php
Last-Modified:      Sun, 12 Feb 2012 23:11:08 GMT
ETag:               "917576a49f4a8bea955ae63e767c31e1"
X-Powered-By:       W3 Total Cache/0.9.1.3
Link:               <http://wp.me/ps4An-sy>; rel=shortlink
Content-Type:       text/xml; charset=UTF-8
-->
