<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for OWASP O2 Platform Blog</title>
	<atom:link href="http://o2platform.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://o2platform.wordpress.com</link>
	<description></description>
	<lastBuildDate>Wed, 20 Mar 2013 23:29:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Exploiting Microsoft MVC vulnerabilities using OWASP O2 Platform by Dinis Cruz</title>
		<link>http://o2platform.wordpress.com/2012/05/20/exploiting-microsoft-mvc-vulnerabilities-using-owasp-o2-platform/#comment-715</link>
		<dc:creator><![CDATA[Dinis Cruz]]></dc:creator>
		<pubDate>Wed, 20 Mar 2013 23:29:31 +0000</pubDate>
		<guid isPermaLink="false">http://o2platform.wordpress.com/?p=1540#comment-715</guid>
		<description><![CDATA[The idea behind using that HTML injection was to automate that process and not require the use of a proxy like fiddler :)

Btw, have you checked the web proxy tool that is in the O2 Scripts folder?]]></description>
		<content:encoded><![CDATA[<p>The idea behind using that HTML injection was to automate that process and not require the use of a proxy like fiddler <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Btw, have you checked the web proxy tool that is in the O2 Scripts folder?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Exploiting Microsoft MVC vulnerabilities using OWASP O2 Platform by Dinis Cruz</title>
		<link>http://o2platform.wordpress.com/2012/05/20/exploiting-microsoft-mvc-vulnerabilities-using-owasp-o2-platform/#comment-714</link>
		<dc:creator><![CDATA[Dinis Cruz]]></dc:creator>
		<pubDate>Wed, 20 Mar 2013 23:27:02 +0000</pubDate>
		<guid isPermaLink="false">http://o2platform.wordpress.com/?p=1540#comment-714</guid>
		<description><![CDATA[It should be possible, that is just an extension method that uses the IE object capability to add HTML to an element 

Another option is to use a JavaScript framework to do it (like jquery)]]></description>
		<content:encoded><![CDATA[<p>It should be possible, that is just an extension method that uses the IE object capability to add HTML to an element </p>
<p>Another option is to use a JavaScript framework to do it (like jquery)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dealing with &#8220;The server committed a protocol violation. Section=ResponseStatusLine&#8221; by The server committed a protocol violation. Section=ResponseHeader Detail=CR must be followed by LF &#171; Nurkartiko</title>
		<link>http://o2platform.wordpress.com/2010/10/20/dealing-with-the-server-committed-a-protocol-violation-sectionresponsestatusline/#comment-710</link>
		<dc:creator><![CDATA[The server committed a protocol violation. Section=ResponseHeader Detail=CR must be followed by LF &#171; Nurkartiko]]></dc:creator>
		<pubDate>Thu, 31 Jan 2013 02:46:37 +0000</pubDate>
		<guid isPermaLink="false">http://o2platform.wordpress.com/?p=69#comment-710</guid>
		<description><![CDATA[[...] Enable/disable useUnsafeHeaderParsing. // See http://o2platform.wordpress.com/2010/10/20/dealing-with-the-server-committed-a-protocol-violation-se... public static bool ToggleAllowUnsafeHeaderParsing(bool enable) { //Get the assembly that contains [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Enable/disable useUnsafeHeaderParsing. // See <a href="http://o2platform.wordpress.com/2010/10/20/dealing-with-the-server-committed-a-protocol-violation-se" rel="nofollow">http://o2platform.wordpress.com/2010/10/20/dealing-with-the-server-committed-a-protocol-violation-se</a>&#8230; public static bool ToggleAllowUnsafeHeaderParsing(bool enable) { //Get the assembly that contains [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FxCop Security rules : A nice to have feature on top of  O2 platform by Dinis Cruz</title>
		<link>http://o2platform.wordpress.com/2012/07/19/fxcop-security-rules-a-nice-to-have-feature-on-top-of-o2-platform/#comment-604</link>
		<dc:creator><![CDATA[Dinis Cruz]]></dc:creator>
		<pubDate>Fri, 20 Jul 2012 05:35:44 +0000</pubDate>
		<guid isPermaLink="false">http://o2platform.wordpress.com/?p=1664#comment-604</guid>
		<description><![CDATA[Here is a reddit to about this article: http://www.reddit.com/r/CatNet/comments/wtxjy/fxcop_security_rules_a_nice_to_have_feature_on/]]></description>
		<content:encoded><![CDATA[<p>Here is a reddit to about this article: <a href="http://www.reddit.com/r/CatNet/comments/wtxjy/fxcop_security_rules_a_nice_to_have_feature_on/" rel="nofollow">http://www.reddit.com/r/CatNet/comments/wtxjy/fxcop_security_rules_a_nice_to_have_feature_on/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Exploiting Microsoft MVC vulnerabilities using OWASP O2 Platform by Michael Hidalgo</title>
		<link>http://o2platform.wordpress.com/2012/05/20/exploiting-microsoft-mvc-vulnerabilities-using-owasp-o2-platform/#comment-588</link>
		<dc:creator><![CDATA[Michael Hidalgo]]></dc:creator>
		<pubDate>Wed, 06 Jun 2012 14:41:46 +0000</pubDate>
		<guid isPermaLink="false">http://o2platform.wordpress.com/?p=1540#comment-588</guid>
		<description><![CDATA[Thanks for your comment. 
There are several ways to inject HTTP Post for fields using the frameworks you mentioned. For Selenium Webdriver, you can inject HTTP form fields by injecting JavaScript. There are some approaches on top of Selenium to achieve this : http://seleniumhq.org/docs/05_selenium_rc.html.
Keep in mind that when working with HTTP POST, rather than sending URL parameters you are sending the  content as a part of the body of the request. For better usage you can capture the local traffic by using &lt;a href=&quot;http://www.fiddler2.com/fiddler2/&quot; title=&quot;Fiddler&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;Fiddler2 &lt;/a&gt; .

Hope this helps.]]></description>
		<content:encoded><![CDATA[<p>Thanks for your comment.<br />
There are several ways to inject HTTP Post for fields using the frameworks you mentioned. For Selenium Webdriver, you can inject HTTP form fields by injecting JavaScript. There are some approaches on top of Selenium to achieve this : <a href="http://seleniumhq.org/docs/05_selenium_rc.html" rel="nofollow">http://seleniumhq.org/docs/05_selenium_rc.html</a>.<br />
Keep in mind that when working with HTTP POST, rather than sending URL parameters you are sending the  content as a part of the body of the request. For better usage you can capture the local traffic by using <a href="http://www.fiddler2.com/fiddler2/" title="Fiddler" target="_blank" rel="nofollow">Fiddler2 </a> .</p>
<p>Hope this helps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Installing O2&#8242;s Visual Studio Add-in, Script environment in Visual Studio IDE by Installing O2′s Visual Studio Add-in, Script environment in Visual Studio IDE &#124; Code to Preload</title>
		<link>http://o2platform.wordpress.com/2012/05/25/installing-o2s-visual-studio-add-in-script-environment-in-visual-studio-ide/#comment-578</link>
		<dc:creator><![CDATA[Installing O2′s Visual Studio Add-in, Script environment in Visual Studio IDE &#124; Code to Preload]]></dc:creator>
		<pubDate>Sun, 27 May 2012 12:00:57 +0000</pubDate>
		<guid isPermaLink="false">http://o2platform.wordpress.com/?p=1620#comment-578</guid>
		<description><![CDATA[[...] Article Source: Installing O2′s Visual Studio Add-in, Script environment in Visual Studio IDE. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Article Source: Installing O2′s Visual Studio Add-in, Script environment in Visual Studio IDE. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Exploiting Microsoft MVC vulnerabilities using OWASP O2 Platform by msiles</title>
		<link>http://o2platform.wordpress.com/2012/05/20/exploiting-microsoft-mvc-vulnerabilities-using-owasp-o2-platform/#comment-577</link>
		<dc:creator><![CDATA[msiles]]></dc:creator>
		<pubDate>Fri, 25 May 2012 17:19:32 +0000</pubDate>
		<guid isPermaLink="false">http://o2platform.wordpress.com/?p=1540#comment-577</guid>
		<description><![CDATA[Sweet, sounds very interesting..... I just have a couple of questions about the automation script, do you guys know if we can do the same fields injection using other automation tools like watir, webdriver etc

I think the magic is on line 72

	Action injectField =
	(fieldName, value)=&gt;{
	ie.field(&quot;FirstName&quot;)
	.injectHtml_afterEnd(&quot;
	{0}:&quot;.format(fieldName, value));
	};]]></description>
		<content:encoded><![CDATA[<p>Sweet, sounds very interesting&#8230;.. I just have a couple of questions about the automation script, do you guys know if we can do the same fields injection using other automation tools like watir, webdriver etc</p>
<p>I think the magic is on line 72</p>
<p>	Action injectField =<br />
	(fieldName, value)=&gt;{<br />
	ie.field(&#8220;FirstName&#8221;)<br />
	.injectHtml_afterEnd(&#8221;<br />
	{0}:&#8221;.format(fieldName, value));<br />
	};</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Automating the Download of a GitHub ZipFile (using IE&#8217;s WatiN) by Dinis Cruz</title>
		<link>http://o2platform.wordpress.com/2012/01/11/automating-the-download-of-a-github-zipfile-using-ies-watin/#comment-575</link>
		<dc:creator><![CDATA[Dinis Cruz]]></dc:creator>
		<pubDate>Fri, 25 May 2012 10:17:38 +0000</pubDate>
		<guid isPermaLink="false">http://o2platform.wordpress.com/?p=1415#comment-575</guid>
		<description><![CDATA[I think you meant it had an extra tag (which I just removed)

Thanks]]></description>
		<content:encoded><![CDATA[<p>I think you meant it had an extra tag (which I just removed)</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Exploiting Microsoft MVC vulnerabilities using OWASP O2 Platform by Michael Hidalgo</title>
		<link>http://o2platform.wordpress.com/2012/05/20/exploiting-microsoft-mvc-vulnerabilities-using-owasp-o2-platform/#comment-570</link>
		<dc:creator><![CDATA[Michael Hidalgo]]></dc:creator>
		<pubDate>Sun, 20 May 2012 04:05:05 +0000</pubDate>
		<guid isPermaLink="false">http://o2platform.wordpress.com/?p=1540#comment-570</guid>
		<description><![CDATA[&lt;p&gt;Reblogged this on &lt;a href=&quot;http://crdevelopment.net/2012/05/19/586/&quot; rel=&quot;nofollow&quot;&gt;Software Engineering in Costa Rica&lt;/a&gt; and commented: &lt;/p&gt;
&lt;p&gt;I just wrote an interesting article about exploiting MVC vulnerabilities using OWASP O2 Platform. Dinis Cruz wrote the great O2 script.&lt;/p&gt;]]></description>
		<content:encoded><![CDATA[<p>Reblogged this on <a href="http://crdevelopment.net/2012/05/19/586/" rel="nofollow">Software Engineering in Costa Rica</a> and commented: </p>
<p>I just wrote an interesting article about exploiting MVC vulnerabilities using OWASP O2 Platform. Dinis Cruz wrote the great O2 script.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Automating the Download of a GitHub ZipFile (using IE&#8217;s WatiN) by fabriciobraz</title>
		<link>http://o2platform.wordpress.com/2012/01/11/automating-the-download-of-a-github-zipfile-using-ies-watin/#comment-569</link>
		<dc:creator><![CDATA[fabriciobraz]]></dc:creator>
		<pubDate>Fri, 18 May 2012 12:01:31 +0000</pubDate>
		<guid isPermaLink="false">http://o2platform.wordpress.com/?p=1415#comment-569</guid>
		<description><![CDATA[In the line 10 from the first code, you missed a &lt;/pre&gt; tag]]></description>
		<content:encoded><![CDATA[<p>In the line 10 from the first code, you missed a  tag</p>
]]></content:encoded>
	</item>
</channel>
</rss>
