<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8539880144347728238.post8428743728097122134..comments</id><updated>2009-04-22T22:28:10.244-04:00</updated><title type='text'>Comments on Carnal0wnage Blog: Owning the Client without an Exploit</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://carnal0wnage.blogspot.com/feeds/8428743728097122134/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default'/><link rel='alternate' type='text/html' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html'/><author><name>CG</name><uri>http://www.blogger.com/profile/11061967917509053185</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8539880144347728238.post-6850910463437256955</id><published>2009-04-22T22:28:00.000-04:00</published><updated>2009-04-22T22:28:00.000-04:00</updated><title type='text'>i know its patched with SP3 but its working for me...</title><content type='html'>i know its patched with SP3 but its working for me with SP2.&lt;br /&gt;&lt;br /&gt;i'll ask dean to take a look at the post</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default/6850910463437256955'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default/6850910463437256955'/><link rel='alternate' type='text/html' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html?showComment=1240453680000#c6850910463437256955' title=''/><author><name>CG</name><uri>http://www.blogger.com/profile/11061967917509053185</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='02636627262990256726'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html' ref='tag:blogger.com,1999:blog-8539880144347728238.post-8428743728097122134' source='http://www.blogger.com/feeds/8539880144347728238/posts/default/8428743728097122134' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8539880144347728238.post-7852454088348693854</id><published>2009-04-22T21:36:00.000-04:00</published><updated>2009-04-22T21:36:00.000-04:00</updated><title type='text'>In IE6 and IE7 default XP SP2 installs I did not g...</title><content type='html'>In IE6 and IE7 default XP SP2 installs I did not get this to work.&lt;br /&gt;&lt;br /&gt;I modified the EXE to a file hosted online.&lt;br /&gt;&lt;br /&gt;If I save the file locally, and open the HTML page then I get an active X prompt, however, after accepting the warning nothing happens.&lt;br /&gt;&lt;br /&gt;What am I doing wrong?&lt;br /&gt;&lt;br /&gt;Thanks&lt;br /&gt;&lt;br /&gt;Anon Steve</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default/7852454088348693854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default/7852454088348693854'/><link rel='alternate' type='text/html' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html?showComment=1240450560000#c7852454088348693854' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html' ref='tag:blogger.com,1999:blog-8539880144347728238.post-8428743728097122134' source='http://www.blogger.com/feeds/8539880144347728238/posts/default/8428743728097122134' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8539880144347728238.post-2362659152143381382</id><published>2008-08-28T21:28:00.000-04:00</published><updated>2008-08-28T21:28:00.000-04:00</updated><title type='text'>Nice Post. Keep up the good work.</title><content type='html'>Nice Post. Keep up the good work.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default/2362659152143381382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default/2362659152143381382'/><link rel='alternate' type='text/html' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html?showComment=1219973280000#c2362659152143381382' title=''/><author><name>KrisTeason</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html' ref='tag:blogger.com,1999:blog-8539880144347728238.post-8428743728097122134' source='http://www.blogger.com/feeds/8539880144347728238/posts/default/8428743728097122134' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8539880144347728238.post-628757667054543638</id><published>2008-08-28T15:32:00.000-04:00</published><updated>2008-08-28T15:32:00.000-04:00</updated><title type='text'>Good catch jay,Yea, I tend to leave a little somet...</title><content type='html'>Good catch jay,&lt;BR/&gt;&lt;BR/&gt;Yea, I tend to leave a little something out. I don't want to make it too easy for them. Same reason I left out actually obfuscating it.&lt;BR/&gt;&lt;BR/&gt;Cheers,&lt;BR/&gt;Dean</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default/628757667054543638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default/628757667054543638'/><link rel='alternate' type='text/html' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html?showComment=1219951920000#c628757667054543638' title=''/><author><name>dean</name><uri>http://www.blogger.com/profile/13744345182407258839</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08521767208495447043'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html' ref='tag:blogger.com,1999:blog-8539880144347728238.post-8428743728097122134' source='http://www.blogger.com/feeds/8539880144347728238/posts/default/8428743728097122134' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8539880144347728238.post-4319383793081860201</id><published>2008-08-28T14:38:00.000-04:00</published><updated>2008-08-28T14:38:00.000-04:00</updated><title type='text'>Don't know if you purposefully meant to leave out ...</title><content type='html'>Don't know if you purposefully meant to leave out a few closing braces (old school bugtraq anti-kiddie technique) ...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default/4319383793081860201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/8428743728097122134/comments/default/4319383793081860201'/><link rel='alternate' type='text/html' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html?showComment=1219948680000#c4319383793081860201' title=''/><author><name>Jay C. James</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html' ref='tag:blogger.com,1999:blog-8539880144347728238.post-8428743728097122134' source='http://www.blogger.com/feeds/8539880144347728238/posts/default/8428743728097122134' type='text/html'/></entry></feed>