<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: CSRF is not XSS!!!</title>
	<atom:link href="http://blog.phishme.com/2007/09/csrf-is-not-xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.phishme.com/2007/09/csrf-is-not-xss/</link>
	<description>Posts about innovative phishing ploys, social engineering techniques, and the latest hacks.  PhishMe is your one stop blog for the latest in anti-phishing and security news.</description>
	<lastBuildDate>Sat, 04 Feb 2012 10:16:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: PhishMe &#187; Myth Buster II: We&#8217;ve Never Been Hacked</title>
		<link>http://blog.phishme.com/2007/09/csrf-is-not-xss/comment-page-1/#comment-60</link>
		<dc:creator>PhishMe &#187; Myth Buster II: We&#8217;ve Never Been Hacked</dc:creator>
		<pubDate>Wed, 31 Oct 2007 21:16:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phishme.com/2007/09/csrf-is-not-xss/#comment-60</guid>
		<description>[...] about Session Riding attacks? In these cases, we have a legitimately logged in user, coming from their normal IP address [...]</description>
		<content:encoded><![CDATA[<p>[...] about Session Riding attacks? In these cases, we have a legitimately logged in user, coming from their normal IP address [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PhishMe &#187; Myth Buster I: Input Validation is a Panacea</title>
		<link>http://blog.phishme.com/2007/09/csrf-is-not-xss/comment-page-1/#comment-59</link>
		<dc:creator>PhishMe &#187; Myth Buster I: Input Validation is a Panacea</dc:creator>
		<pubDate>Mon, 29 Oct 2007 15:14:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.phishme.com/2007/09/csrf-is-not-xss/#comment-59</guid>
		<description>[...] Benninger explained the difference between the often confused XSS and XSRF in a previous blog post. The root cause of XSRF is the predicability of key HTTP requests that result in transactions with [...]</description>
		<content:encoded><![CDATA[<p>[...] Benninger explained the difference between the often confused XSS and XSRF in a previous blog post. The root cause of XSRF is the predicability of key HTTP requests that result in transactions with [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

