<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Internet Strategy Guide &#187; twitter</title>
	<atom:link href="http://phpprotip.com/category/web-dev/twitter/feed/" rel="self" type="application/rss+xml" />
	<link>http://phpprotip.com</link>
	<description>Together we can defeat the internet</description>
	<lastBuildDate>Fri, 20 Aug 2010 18:15:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>openid seems to hate me</title>
		<link>http://phpprotip.com/2009/02/openid-seems-to-hate-me/</link>
		<comments>http://phpprotip.com/2009/02/openid-seems-to-hate-me/#comments</comments>
		<pubDate>Thu, 12 Feb 2009 19:40:04 +0000</pubDate>
		<dc:creator>chance</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[clickjack]]></category>
		<category><![CDATA[csrf]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://phpprotip.com/?p=115</guid>
		<description><![CDATA[been trying to comment on Chris Shiflett's post on the twitter "Don't Click" debacle and can't seem to get authenticated through openid. so having to post my reply here (below). cavaet: i'm not an expert on anything and a n00b at a lot of things liked the article, however I want to disagree that it [...]]]></description>
			<content:encoded><![CDATA[<p>been trying to comment on <a href="http://phpprotip.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?url=aHR0cDovL3NoaWZsZXR0Lm9yZy9ibG9nLzIwMDkvZmViL3R3aXR0ZXItZG9udC1jbGljay1leHBsb2l0">Chris Shiflett's post on the twitter "Don't Click" debacle</a> and can't seem to get authenticated through openid. so having to post my reply here (below).</p>
<p>cavaet: i'm not an expert on anything and a n00b at a lot of things</p>
<p>liked the article, however I want to disagree that it isn't a csrf attack since "The attack works by including a link or script in a page that accesses a site to which the user is known (or is supposed) to have authenticated" (according to wikipedia [oh no, i'm that guy. *sigh*]). @ramsey said it didn't affect him because he wasn't logged in on the website.</p>
<p>It seems to me that it used clickjack ui redressing to carry out the authentication exploit.</p>
<p>Want to know the funny thing? The only reason I logged into the website was to follow @shiflett.</p>
 <img src="http://phpprotip.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=115" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://phpprotip.com/2009/02/openid-seems-to-hate-me/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
