<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>TetraBlog - Comments</title>
    <link>http://www.tetraboy.com/</link>
    <description>TetraBlog - Five nines of awesome.</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.1.2 - http://www.s9y.org/</generator>
    <pubDate>Wed, 10 Mar 2010 13:30:41 GMT</pubDate>

    <image>
        <url>http://www.tetraboy.com/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: TetraBlog - Comments - TetraBlog - Five nines of awesome.</title>
        <link>http://www.tetraboy.com/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Jeff Jones: Twitter Clickjacking &quot;Attack&quot;</title>
    <link>http://www.tetraboy.com/archives/5-Twitter-Clickjacking-Attack.html#c913</link>
            <category></category>
    
    <comments>http://www.tetraboy.com/archives/5-Twitter-Clickjacking-Attack.html#comments</comments>
    <wfw:comment>http://www.tetraboy.com/wfwcomment.php?cid=5</wfw:comment>

    

    <author>nospam@example.com (Jeff Jones)</author>
    <content:encoded>
    As a followup, twitter has since changed tactics from frame busting to blanking the page if it&#039;s detected to be running in frames. It looks like the new fix would be harder to override in JS, though there are possible ways around it via hanging javascript or timing attacks, but it&#039;s much better than the frame busting. This clickjacking still works on browsers without javascript!&lt;br /&gt;
&lt;br /&gt;
I would still prefer a server-side method such as &quot;site-specific captcha&quot; for lack of a better term. This would only need to be used in cases of a pre-populated form without valid tokens. Standard tweets and replies could be excepted from it. 
    </content:encoded>

    <pubDate>Fri, 13 Feb 2009 13:48:31 -0600</pubDate>
    <guid isPermaLink="false">http://www.tetraboy.com/archives/5-guid.html#c913</guid>
    
</item>
<item>
    <title>Tetraboy: 7 things you didn't know, or want to know, about me.</title>
    <link>http://www.tetraboy.com/archives/4-7-things-you-didnt-know,-or-want-to-know,-about-me..html#c847</link>
            <category></category>
    
    <comments>http://www.tetraboy.com/archives/4-7-things-you-didnt-know,-or-want-to-know,-about-me..html#comments</comments>
    <wfw:comment>http://www.tetraboy.com/wfwcomment.php?cid=4</wfw:comment>

    

    <author>nospam@example.com (Tetraboy)</author>
    <content:encoded>
    I did include &quot;popular&quot; name for a bit of CYA.. I believe I found out about it back around 2001-2002. So while there may have been a name for it, it really wasn&#039;t as widely known as it is today. 
    </content:encoded>

    <pubDate>Sun, 04 Jan 2009 12:15:17 -0600</pubDate>
    <guid isPermaLink="false">http://www.tetraboy.com/archives/4-guid.html#c847</guid>
    
</item>
<item>
    <title>Chris Shiflett: 7 things you didn't know, or want to know, about me.</title>
    <link>http://www.tetraboy.com/archives/4-7-things-you-didnt-know,-or-want-to-know,-about-me..html#c846</link>
            <category></category>
    
    <comments>http://www.tetraboy.com/archives/4-7-things-you-didnt-know,-or-want-to-know,-about-me..html#comments</comments>
    <wfw:comment>http://www.tetraboy.com/wfwcomment.php?cid=4</wfw:comment>

    

    <author>nospam@example.com (Chris Shiflett)</author>
    <content:encoded>
    CSRF was being talked about over 7 years ago:&lt;br /&gt;
&lt;br /&gt;
http://www.tux.org/~peterw/csrf.txt&lt;br /&gt;
&lt;br /&gt;
It was talked about in php|architect over 5 years ago:&lt;br /&gt;
&lt;br /&gt;
http://shiflett.org/articles/foiling-cross-site-attacks&lt;br /&gt;
&lt;br /&gt;
Are you sure you discovered it before it had a name? 
    </content:encoded>

    <pubDate>Sun, 04 Jan 2009 11:22:30 -0600</pubDate>
    <guid isPermaLink="false">http://www.tetraboy.com/archives/4-guid.html#c846</guid>
    
</item>
<item>
    <title>Tetraboy: Arrays are Objects are Functions are Objects?</title>
    <link>http://www.tetraboy.com/archives/3-Arrays-are-Objects-are-Functions-are-Objects.html#c845</link>
            <category></category>
    
    <comments>http://www.tetraboy.com/archives/3-Arrays-are-Objects-are-Functions-are-Objects.html#comments</comments>
    <wfw:comment>http://www.tetraboy.com/wfwcomment.php?cid=3</wfw:comment>

    

    <author>nospam@example.com (Tetraboy)</author>
    <content:encoded>
    Thanks Remi. That post was over a year old. I meant to write a followup saying how I did eventually figure out Javascript, but I never got around to it. 
    </content:encoded>

    <pubDate>Sat, 03 Jan 2009 20:27:59 -0600</pubDate>
    <guid isPermaLink="false">http://www.tetraboy.com/archives/3-guid.html#c845</guid>
    
</item>
<item>
    <title>Remi Woler: Arrays are Objects are Functions are Objects?</title>
    <link>http://www.tetraboy.com/archives/3-Arrays-are-Objects-are-Functions-are-Objects.html#c843</link>
            <category></category>
    
    <comments>http://www.tetraboy.com/archives/3-Arrays-are-Objects-are-Functions-are-Objects.html#comments</comments>
    <wfw:comment>http://www.tetraboy.com/wfwcomment.php?cid=3</wfw:comment>

    

    <author>nospam@example.com (Remi Woler)</author>
    <content:encoded>
    Arrays are &lt;strong&gt;not&lt;/strong&gt; objects in javascript. You have simple types, arrays, and objects. The fact that you can access object variables the way you access arrays in PHP doesn&#039;t mean it&#039;s suddenly an array. For a very clear description on Arrays and JSON (Objects), you might want to check out [url=&quot;http://www.hunlock.com/blogs/Mastering_Javascript_Arrays&quot;]hunlock.com[/url]. This site has taught me the differences, and how to work with them, and I still use it every now and then as a quick reference. (Hint: keywords &quot;mastering javascript [arrays|json] brings this site as #1 result in google) 
    </content:encoded>

    <pubDate>Sat, 03 Jan 2009 16:28:55 -0600</pubDate>
    <guid isPermaLink="false">http://www.tetraboy.com/archives/3-guid.html#c843</guid>
    
</item>

</channel>
</rss>