<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2914337944584630860.post3008456550161732006..comments</id><updated>2009-11-14T22:14:54.350-08:00</updated><title type='text'>Comments on Jon Hart's Blog: Name-based Virtual Hosting and Web Application Sec...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.spoofed.org/feeds/3008456550161732006/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3008456550161732006/comments/default'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2009/01/name-based-virtual-hosting-and-web.html'/><author><name>Jon Hart</name><uri>http://www.blogger.com/profile/02857880233692933624</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-6517438852359041538</id><published>2009-01-28T08:44:00.000-08:00</published><updated>2009-01-28T08:44:00.000-08:00</updated><title type='text'>@LonerVamp:  yeah, great point about SSL.  It supp...</title><content type='html'>@LonerVamp:  yeah, great point about SSL.  It supports SSL right now, but does not look at the handful of fields that may contain other hostnames/IPs to probe.  &lt;BR/&gt;&lt;BR/&gt;Thinking about this, my code may be more appropriate as a patch to &lt;A HREF="http://www.cirt.net/nikto2" REL="nofollow"&gt;Nikto&lt;/A&gt;.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3008456550161732006/comments/default/6517438852359041538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3008456550161732006/comments/default/6517438852359041538'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2009/01/name-based-virtual-hosting-and-web.html?showComment=1233161040000#c6517438852359041538' title=''/><author><name>Jon Hart</name><uri>http://www.blogger.com/profile/03410754059921403771</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2009/01/name-based-virtual-hosting-and-web.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3008456550161732006' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3008456550161732006' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-7871550482011653885</id><published>2009-01-27T12:37:00.000-08:00</published><updated>2009-01-27T12:37:00.000-08:00</updated><title type='text'>You could also try throwing in an https/443 reques...</title><content type='html'>You could also try throwing in an https/443 request and see where that takes you. Even sites that properly manage hosts can mismanage the SSL portion. The SSL cert may give away another site or a company name, etc.&lt;BR/&gt;&lt;BR/&gt;Interestingly, if you expose to the outside world a site that is meant to only be viewed internally, if it is the one that comes up when an invalid host is sent. Eep!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3008456550161732006/comments/default/7871550482011653885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3008456550161732006/comments/default/7871550482011653885'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2009/01/name-based-virtual-hosting-and-web.html?showComment=1233088620000#c7871550482011653885' title=''/><author><name>LonerVamp</name><uri>http://www.blogger.com/profile/15357840241031190415</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2009/01/name-based-virtual-hosting-and-web.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3008456550161732006' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3008456550161732006' type='text/html'/></entry></feed>