<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Episode 13 &#8211; Website Hacking &#8211; XSS</title>
	<atom:link href="http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/</link>
	<description>Infinity Exists strives to disclose common hacking methods through easy to understand videos.</description>
	<lastBuildDate>Thu, 19 Jan 2012 17:52:52 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Patchy</title>
		<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/comment-page-1/#comment-39684</link>
		<dc:creator>Patchy</dc:creator>
		<pubDate>Fri, 02 Jan 2009 00:37:07 +0000</pubDate>
		<guid isPermaLink="false">http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/#comment-39684</guid>
		<description>http://infinityexists.com/downloads/cookie</description>
		<content:encoded><![CDATA[<p><a href="http://infinityexists.com/downloads/cookie" rel="nofollow">http://infinityexists.com/downloads/cookie</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: demonicspawn</title>
		<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/comment-page-1/#comment-39683</link>
		<dc:creator>demonicspawn</dc:creator>
		<pubDate>Thu, 01 Jan 2009 15:02:15 +0000</pubDate>
		<guid isPermaLink="false">http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/#comment-39683</guid>
		<description>sup dude...i contacted u on youtube ...but i need some help over here...can u give me the cookie catcher php file dude???plz ...cuz i get a error on line 4....

i mean the original file!!</description>
		<content:encoded><![CDATA[<p>sup dude&#8230;i contacted u on youtube &#8230;but i need some help over here&#8230;can u give me the cookie catcher php file dude???plz &#8230;cuz i get a error on line 4&#8230;.</p>
<p>i mean the original file!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scotted</title>
		<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/comment-page-1/#comment-39669</link>
		<dc:creator>Scotted</dc:creator>
		<pubDate>Mon, 08 Dec 2008 09:36:19 +0000</pubDate>
		<guid isPermaLink="false">http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/#comment-39669</guid>
		<description>A BIG THANKS TO PATCHY !!!! THANK YOU A MILLION TIMES, it has worked and now I am able to sleep :D</description>
		<content:encoded><![CDATA[<p>A BIG THANKS TO PATCHY !!!! THANK YOU A MILLION TIMES, it has worked and now I am able to sleep <img src='http://infinityexists.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scotted</title>
		<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/comment-page-1/#comment-39665</link>
		<dc:creator>Scotted</dc:creator>
		<pubDate>Wed, 03 Dec 2008 07:54:24 +0000</pubDate>
		<guid isPermaLink="false">http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/#comment-39665</guid>
		<description>This is what I thought too until I have tried to reinject my own cookie from another computer in my network with the same IP address and the website still does not recognize me :(</description>
		<content:encoded><![CDATA[<p>This is what I thought too until I have tried to reinject my own cookie from another computer in my network with the same IP address and the website still does not recognize me <img src='http://infinityexists.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patchy</title>
		<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/comment-page-1/#comment-39664</link>
		<dc:creator>Patchy</dc:creator>
		<pubDate>Mon, 01 Dec 2008 21:53:29 +0000</pubDate>
		<guid isPermaLink="false">http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/#comment-39664</guid>
		<description>@Scotted: Most likely the cookies are based on the user&#039;s IP Address.  In that situation you are better off trying the XSS Tunnel attack.
@Hackncrack:  That is a great question.  That feature should definitely be added to password crackers!</description>
		<content:encoded><![CDATA[<p>@Scotted: Most likely the cookies are based on the user&#8217;s IP Address.  In that situation you are better off trying the XSS Tunnel attack.<br />
@Hackncrack:  That is a great question.  That feature should definitely be added to password crackers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackncrack</title>
		<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/comment-page-1/#comment-39663</link>
		<dc:creator>hackncrack</dc:creator>
		<pubDate>Mon, 01 Dec 2008 17:53:44 +0000</pubDate>
		<guid isPermaLink="false">http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/#comment-39663</guid>
		<description>wait, so why arent there any programs for cracking passwords that will do the double encryption for you? its the same process as a normal brute force or dictionary attack? it just has to encrypt it twice? or am i getting the process wrong?

ex: first word in dictionary is &quot;apple&quot; so all the computer has to do is:

apple
--hash to md5--
1f3870be274f6c49b3e31a0c6728957f
--hash to md5 again--
ae6d32585ecc4d33cb8cd68a047d8434
--compares ^ to extracted hash--</description>
		<content:encoded><![CDATA[<p>wait, so why arent there any programs for cracking passwords that will do the double encryption for you? its the same process as a normal brute force or dictionary attack? it just has to encrypt it twice? or am i getting the process wrong?</p>
<p>ex: first word in dictionary is &#8220;apple&#8221; so all the computer has to do is:</p>
<p>apple<br />
&#8211;hash to md5&#8211;<br />
1f3870be274f6c49b3e31a0c6728957f<br />
&#8211;hash to md5 again&#8211;<br />
ae6d32585ecc4d33cb8cd68a047d8434<br />
&#8211;compares ^ to extracted hash&#8211;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scotted</title>
		<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/comment-page-1/#comment-39662</link>
		<dc:creator>Scotted</dc:creator>
		<pubDate>Sun, 30 Nov 2008 04:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/#comment-39662</guid>
		<description>Hey Patchy, really nice video...
But do you have any ideas why reinjecting a stolen cookie doesnt work , I mean the website doesn&#039;t identify me at all and if I try to reinject my own cookie (grabbed from the same computer I signed in ) works ?</description>
		<content:encoded><![CDATA[<p>Hey Patchy, really nice video&#8230;<br />
But do you have any ideas why reinjecting a stolen cookie doesnt work , I mean the website doesn&#8217;t identify me at all and if I try to reinject my own cookie (grabbed from the same computer I signed in ) works ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: joemama</title>
		<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/comment-page-1/#comment-4580</link>
		<dc:creator>joemama</dc:creator>
		<pubDate>Mon, 14 Apr 2008 23:55:31 +0000</pubDate>
		<guid isPermaLink="false">http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/#comment-4580</guid>
		<description>i need help using t35 and uploading the cookie cathcer someone please help</description>
		<content:encoded><![CDATA[<p>i need help using t35 and uploading the cookie cathcer someone please help</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: aj atkinson</title>
		<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/comment-page-1/#comment-1144</link>
		<dc:creator>aj atkinson</dc:creator>
		<pubDate>Wed, 30 Jan 2008 21:55:05 +0000</pubDate>
		<guid isPermaLink="false">http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/#comment-1144</guid>
		<description>so you mean that basically they are hashed 2 times??? That&#039;s wild. I have always wondered what algorithm most cookies were encoded with, myspace, hotmail, etc. I have always tried to use cain or mdcrack to decode my own cookies just for the hell of it and never could. That is probabbly why LOL</description>
		<content:encoded><![CDATA[<p>so you mean that basically they are hashed 2 times??? That&#8217;s wild. I have always wondered what algorithm most cookies were encoded with, myspace, hotmail, etc. I have always tried to use cain or mdcrack to decode my own cookies just for the hell of it and never could. That is probabbly why LOL</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patchy</title>
		<link>http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/comment-page-1/#comment-917</link>
		<dc:creator>Patchy</dc:creator>
		<pubDate>Tue, 20 Nov 2007 22:02:45 +0000</pubDate>
		<guid isPermaLink="false">http://infinityexists.com/2007/11/16/episode-13-website-hacking-xss/#comment-917</guid>
		<description>Well it is possible... The cookie password in wordpress is the md5 hash of the md5 hash of your password, so it would be very hard to crack.</description>
		<content:encoded><![CDATA[<p>Well it is possible&#8230; The cookie password in wordpress is the md5 hash of the md5 hash of your password, so it would be very hard to crack.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

