<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: My SQL Exfiltrating Data Over Out Of Band Channels(OOB)</title>
	<atom:link href="http://www.notsosecure.com/folder2/2009/02/13/my-sql-exfiltrating-data-over-out-of-band-channelsoob/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.notsosecure.com/folder2/2009/02/13/my-sql-exfiltrating-data-over-out-of-band-channelsoob/</link>
	<description>From Pentesters To Pentesters</description>
	<lastBuildDate>Sun, 22 Aug 2010 14:39:55 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: kuza55</title>
		<link>http://www.notsosecure.com/folder2/2009/02/13/my-sql-exfiltrating-data-over-out-of-band-channelsoob/comment-page-1/#comment-76328</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Wed, 04 Mar 2009 11:59:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=180#comment-76328</guid>
		<description>Do you know what preconditions need to be satisfied for the app to start sending NTLM credentials? I assume they have to be domain joined, but is there anything else? And do you know how IE has fixed this to stop internet sites from getting user hashes?

Given windows file functionality interprets UNC paths natively, this seems like something that could be utilised to hack a whole lot of other software...</description>
		<content:encoded><![CDATA[<p>Do you know what preconditions need to be satisfied for the app to start sending NTLM credentials? I assume they have to be domain joined, but is there anything else? And do you know how IE has fixed this to stop internet sites from getting user hashes?</p>
<p>Given windows file functionality interprets UNC paths natively, this seems like something that could be utilised to hack a whole lot of other software&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reiners</title>
		<link>http://www.notsosecure.com/folder2/2009/02/13/my-sql-exfiltrating-data-over-out-of-band-channelsoob/comment-page-1/#comment-71945</link>
		<dc:creator>Reiners</dc:creator>
		<pubDate>Wed, 18 Feb 2009 17:50:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=180#comment-71945</guid>
		<description>very nice :) I remember playing with this before but I couldnt get it working at that time.</description>
		<content:encoded><![CDATA[<p>very nice <img src='http://www.notsosecure.com/folder2/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I remember playing with this before but I couldnt get it working at that time.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
