<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Google: Chili&#8217;s.com &#8220;may harm your computer&#8221;</title>
	<atom:link href="http://ineedattention.com/technology/2008/07/27/google-chiliscom-may-harm-your-computer/feed/" rel="self" type="application/rss+xml" />
	<link>http://ineedattention.com/technology/2008/07/27/google-chiliscom-may-harm-your-computer/</link>
	<description>Rants on business, science, technology, society, politics, police, and justice, plus life hacks and tricks, since 2003.</description>
	<lastBuildDate>Tue, 24 Aug 2010 21:14:41 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: m</title>
		<link>http://ineedattention.com/technology/2008/07/27/google-chiliscom-may-harm-your-computer/comment-page-1/#comment-13171</link>
		<dc:creator>m</dc:creator>
		<pubDate>Thu, 31 Jul 2008 04:29:16 +0000</pubDate>
		<guid isPermaLink="false">http://ineedattention.com/?p=229#comment-13171</guid>
		<description>Cross site scripting is the answer.. if I was bored I could redirect your order to my server and rip your card then send it to Chili&#039;s.. Theoretically. You would still get your salad.

http://en.wikipedia.org/wiki/Cross-site_scripting

EDITOR&#039;S REPLY: That&#039;s a sensible theory, except that you can&#039;t actually order online at Chili&#039;s website, you have to actually call your local Chili&#039;s to order, and you pay at the restaurant when you pick it up.  It looks like their website just got hacked the old fashion way (exploiting some off-the-shelf software Chili&#039;s was using to host their page), and some Russian spammers were able to inject a drive-by download into the source.</description>
		<content:encoded><![CDATA[<p>Cross site scripting is the answer.. if I was bored I could redirect your order to my server and rip your card then send it to Chili&#8217;s.. Theoretically. You would still get your salad.</p>
<p><a href="http://en.wikipedia.org/wiki/Cross-site_scripting" rel="nofollow">http://en.wikipedia.org/wiki/Cross-site_scripting</a></p>
<p>EDITOR&#8217;S REPLY: That&#8217;s a sensible theory, except that you can&#8217;t actually order online at Chili&#8217;s website, you have to actually call your local Chili&#8217;s to order, and you pay at the restaurant when you pick it up.  It looks like their website just got hacked the old fashion way (exploiting some off-the-shelf software Chili&#8217;s was using to host their page), and some Russian spammers were able to inject a drive-by download into the source.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
