<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ST701.com Classified Hack Part 2</title>
	<atom:link href="http://www.hanneng.net/2007/11/28/st701com-classified-portal-hack-part-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hanneng.net/2007/11/28/st701com-classified-portal-hack-part-2/</link>
	<description>Whatever and Anything</description>
	<lastBuildDate>Thu, 22 Dec 2011 09:44:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: hanneng</title>
		<link>http://www.hanneng.net/2007/11/28/st701com-classified-portal-hack-part-2/#comment-8666</link>
		<dc:creator>hanneng</dc:creator>
		<pubDate>Wed, 28 Nov 2007 04:14:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.hanneng.net/2007/11/28/st701com-classified-portal-hack-part-2/#comment-8666</guid>
		<description>Hi Bug,

Thanks for your comments. 

I do aware that there is security concern in this method as I failed to highlight in the blog post.</description>
		<content:encoded><![CDATA[<p>Hi Bug,</p>
<p>Thanks for your comments. </p>
<p>I do aware that there is security concern in this method as I failed to highlight in the blog post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bug</title>
		<link>http://www.hanneng.net/2007/11/28/st701com-classified-portal-hack-part-2/#comment-8665</link>
		<dc:creator>Bug</dc:creator>
		<pubDate>Wed, 28 Nov 2007 04:07:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.hanneng.net/2007/11/28/st701com-classified-portal-hack-part-2/#comment-8665</guid>
		<description>Oh by the way, don&#039;t worry about people using this method to break ST701. It seems that the calls you are making are all valid HTTP operations, either POST or GET, with simple substitutions -- nothing illegal, just automated on the commandline instead of done manually through the browser. Nothing that ST701 should be able to block either.</description>
		<content:encoded><![CDATA[<p>Oh by the way, don&#8217;t worry about people using this method to break ST701. It seems that the calls you are making are all valid HTTP operations, either POST or GET, with simple substitutions &#8212; nothing illegal, just automated on the commandline instead of done manually through the browser. Nothing that ST701 should be able to block either.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bug</title>
		<link>http://www.hanneng.net/2007/11/28/st701com-classified-portal-hack-part-2/#comment-8663</link>
		<dc:creator>Bug</dc:creator>
		<pubDate>Wed, 28 Nov 2007 03:59:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.hanneng.net/2007/11/28/st701com-classified-portal-hack-part-2/#comment-8663</guid>
		<description>In your first screenshot it looks like you&#039;re POSTing to ST701.com over an insecure connection. The POST address is of http:// and not https://. While you deserve kudos for a decent automation hack, do note (as I&#039;m sure you&#039;re aware) that POSTing userids and passwords in the clear leaves them open to network sniffers. I&#039;m surprised that ST701 hasn&#039;t taken greater efforts to secure their users&#039; accounts.</description>
		<content:encoded><![CDATA[<p>In your first screenshot it looks like you&#8217;re POSTing to ST701.com over an insecure connection. The POST address is of http:// and not https://. While you deserve kudos for a decent automation hack, do note (as I&#8217;m sure you&#8217;re aware) that POSTing userids and passwords in the clear leaves them open to network sniffers. I&#8217;m surprised that ST701 hasn&#8217;t taken greater efforts to secure their users&#8217; accounts.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

