<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Prevent Blogspam in MoveableType using Flash	</title>
	<atom:link href="https://jessewarden.com/2004/12/prevent-blogspam-in-moveabletype-using-flash.html/feed" rel="self" type="application/rss+xml" />
	<link>https://jessewarden.com/2004/12/prevent-blogspam-in-moveabletype-using-flash.html</link>
	<description>Software &#124; Fitness &#124; Gaming</description>
	<lastBuildDate>Sat, 15 Dec 2007 17:15:32 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>
		By: JesterXL		</title>
		<link>https://jessewarden.com/2004/12/prevent-blogspam-in-moveabletype-using-flash.html/comment-page-1#comment-2215</link>

		<dc:creator><![CDATA[JesterXL]]></dc:creator>
		<pubDate>Mon, 02 Oct 2006 16:48:25 +0000</pubDate>
		<guid isPermaLink="false">http://jessewarden.com/?p=680#comment-2215</guid>

					<description><![CDATA[Nice one, Nick!  After 20 months, someone finally figured it out. 
]]></description>
			<content:encoded><![CDATA[<p>Nice one, Nick!  After 20 months, someone finally figured it out. </p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Nick Williams, yet again		</title>
		<link>https://jessewarden.com/2004/12/prevent-blogspam-in-moveabletype-using-flash.html/comment-page-1#comment-2214</link>

		<dc:creator><![CDATA[Nick Williams, yet again]]></dc:creator>
		<pubDate>Mon, 02 Oct 2006 06:58:46 +0000</pubDate>
		<guid isPermaLink="false">http://jessewarden.com/?p=680#comment-2214</guid>

					<description><![CDATA[1) you could simply automate the posting by snagging the entry ID from this page&#039;s html source, and using it with this 

2) You could craft a url on-the-fly, &lt;a href=&#039;http://www.jessewarden.com/cgi-bin/moveabletype/mt-comments.cgi?secretvizznar=else89ford04&#038;static=1&#038;post=submit&#038;entry%5Fid=676&#038;text=%3CFONT%20FACE%3D%22%5Fsans%22%20SIZE%3D%2211%22%20COLOR%3D%22%23000000%22%20LETTERSPACING%3D%220%22%20KERNING%3D%220%22%3EThis%20comment%20was%20posted%20by%20simply%20clicking%20the%20link%20in%20Nick%20William%27s%20comment%20on%20this%20page%2E&#038;author=The%20link%20in%20Nick%27s%20comment&#039; rel=&quot;nofollow&quot;&gt;like this one&lt;/a&gt;, that would post a comment.

The fact of the matter remains that this method will never be secure if it is ultimately accessing a URL that is not guarded from such an attack.  It will only be useful on blogs that are not currently targets of spam.  And, if I were a spammer, all blogs that had this flash file would now be a target.]]></description>
			<content:encoded><![CDATA[<p>1) you could simply automate the posting by snagging the entry ID from this page&#8217;s html source, and using it with this </p>
<p>2) You could craft a url on-the-fly, <a href='http://www.jessewarden.com/cgi-bin/moveabletype/mt-comments.cgi?secretvizznar=else89ford04&amp;static=1&amp;post=submit&amp;entry%5Fid=676&amp;text=%3CFONT%20FACE%3D%22%5Fsans%22%20SIZE%3D%2211%22%20COLOR%3D%22%23000000%22%20LETTERSPACING%3D%220%22%20KERNING%3D%220%22%3EThis%20comment%20was%20posted%20by%20simply%20clicking%20the%20link%20in%20Nick%20William%27s%20comment%20on%20this%20page%2E&amp;author=The%20link%20in%20Nick%27s%20comment' rel="nofollow">like this one</a>, that would post a comment.</p>
<p>The fact of the matter remains that this method will never be secure if it is ultimately accessing a URL that is not guarded from such an attack.  It will only be useful on blogs that are not currently targets of spam.  And, if I were a spammer, all blogs that had this flash file would now be a target.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Nick Williams		</title>
		<link>https://jessewarden.com/2004/12/prevent-blogspam-in-moveabletype-using-flash.html/comment-page-1#comment-2213</link>

		<dc:creator><![CDATA[Nick Williams]]></dc:creator>
		<pubDate>Mon, 02 Oct 2006 06:28:54 +0000</pubDate>
		<guid isPermaLink="false">http://jessewarden.com/?p=680#comment-2213</guid>

					<description><![CDATA[The answer is: not much.

Your secret key is &#039;else89ford04&#039;.

This could be automated very easily by searching the html source for your swf file, then altering the parameters so that it sends the data to my own server.  At which point, I could then craft the URL to post directly to your blog.]]></description>
			<content:encoded><![CDATA[<p>The answer is: not much.</p>
<p>Your secret key is &#8216;else89ford04&#8217;.</p>
<p>This could be automated very easily by searching the html source for your swf file, then altering the parameters so that it sends the data to my own server.  At which point, I could then craft the URL to post directly to your blog.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Nick Williams		</title>
		<link>https://jessewarden.com/2004/12/prevent-blogspam-in-moveabletype-using-flash.html/comment-page-1#comment-2212</link>

		<dc:creator><![CDATA[Nick Williams]]></dc:creator>
		<pubDate>Mon, 02 Oct 2006 06:26:35 +0000</pubDate>
		<guid isPermaLink="false">http://jessewarden.com/?p=680#comment-2212</guid>

					<description><![CDATA[What prevents me from listening in or using Firefox&#039;s TamperData plugin to determine what your flash file is sending?]]></description>
			<content:encoded><![CDATA[<p>What prevents me from listening in or using Firefox&#8217;s TamperData plugin to determine what your flash file is sending?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: aasdfasf		</title>
		<link>https://jessewarden.com/2004/12/prevent-blogspam-in-moveabletype-using-flash.html/comment-page-1#comment-2211</link>

		<dc:creator><![CDATA[aasdfasf]]></dc:creator>
		<pubDate>Mon, 02 Oct 2006 06:24:28 +0000</pubDate>
		<guid isPermaLink="false">http://jessewarden.com/?p=680#comment-2211</guid>

					<description><![CDATA[asfasdfs]]></description>
			<content:encoded><![CDATA[<p>asfasdfs</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
