<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Token Kidnapping finally patched!</title><link>http://blogs.technet.com/bluehat/archive/2009/04/14/token-kidnapping-finally-patched.aspx</link><description>Here I am again writing on MS BlueHat blog, this time about Token Kidnapping. The first time I talked about Token kidnapping was a long time ago and now after a year the issues detailed in the presentation are finally fixed. Let's see what happened. Before</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Token Kidnapping finally patched!</title><link>http://blogs.technet.com/bluehat/archive/2009/04/14/token-kidnapping-finally-patched.aspx#3234900</link><pubDate>Mon, 04 May 2009 17:54:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3234900</guid><dc:creator>gazanga</dc:creator><description>&lt;p&gt;I'm glad this issue was resolved. &amp;nbsp;I'm sure there could have been a quicker fix, but to resolve this in such a way to conform to RFC standards, and to avoid creating bigger problems, likely required additional work and patience. &amp;nbsp;I, for one, appreciate the candor and full-disclosure of your post, Mr. Cerrudo.&lt;/p&gt;</description></item></channel></rss>