<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 0day Full disclosure: American Express</title>
	<atom:link href="http://qnrq.se/full-disclosure-american-express/feed/" rel="self" type="application/rss+xml" />
	<link>http://qnrq.se/full-disclosure-american-express/</link>
	<description></description>
	<lastBuildDate>Mon, 06 May 2013 14:01:45 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: M</title>
		<link>http://qnrq.se/full-disclosure-american-express/#comment-14302</link>
		<dc:creator>M</dc:creator>
		<pubDate>Tue, 14 Aug 2012 01:55:03 +0000</pubDate>
		<guid isPermaLink="false">http://qnrq.se/?p=91#comment-14302</guid>
		<description><![CDATA[Just wanted to let you know the right thing.

To the haters:

Realize other people besides the author could already know about this and be exploiting it. By him disclosing it publicly not only is the company aware, but so are you. Now you can both take measures to prevent an attack.]]></description>
		<content:encoded><![CDATA[<p>Just wanted to let you know the right thing.</p>
<p>To the haters:</p>
<p>Realize other people besides the author could already know about this and be exploiting it. By him disclosing it publicly not only is the company aware, but so are you. Now you can both take measures to prevent an attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How to Make Customer Service Matter Again Part 2 - Brian Solis</title>
		<link>http://qnrq.se/full-disclosure-american-express/#comment-13773</link>
		<dc:creator>How to Make Customer Service Matter Again Part 2 - Brian Solis</dc:creator>
		<pubDate>Sun, 29 Jul 2012 18:01:47 +0000</pubDate>
		<guid isPermaLink="false">http://qnrq.se/?p=91#comment-13773</guid>
		<description><![CDATA[[...] but did not have time or patience to go through a &#8220;technical support jungle?&#8221; He blogged not only about the experience, but he also exposed the code and tipped security publications [...]]]></description>
		<content:encoded><![CDATA[<p>[...] but did not have time or patience to go through a &#8220;technical support jungle?&#8221; He blogged not only about the experience, but he also exposed the code and tipped security publications [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: InfoTech IT Development Blog &#187; Blog Archive &#187; How Security Relates to Your Brand</title>
		<link>http://qnrq.se/full-disclosure-american-express/#comment-337</link>
		<dc:creator>InfoTech IT Development Blog &#187; Blog Archive &#187; How Security Relates to Your Brand</dc:creator>
		<pubDate>Thu, 27 Oct 2011 21:23:53 +0000</pubDate>
		<guid isPermaLink="false">http://qnrq.se/?p=91#comment-337</guid>
		<description><![CDATA[[...] the problem you need to beware of isn’t just what can be done. It’s also about how bad someone can make your brand look with a post to a website after they have found issues. Depending on your business &#8212; it’s [...]]]></description>
		<content:encoded><![CDATA[<p>[...] the problem you need to beware of isn’t just what can be done. It’s also about how bad someone can make your brand look with a post to a website after they have found issues. Depending on your business &#8212; it’s [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wes</title>
		<link>http://qnrq.se/full-disclosure-american-express/#comment-325</link>
		<dc:creator>Wes</dc:creator>
		<pubDate>Wed, 26 Oct 2011 20:59:53 +0000</pubDate>
		<guid isPermaLink="false">http://qnrq.se/?p=91#comment-325</guid>
		<description><![CDATA[@Anthony,
Not sure when you checked Discover Card last but when I visit discover.com I am automatically redirected to https://www.discover.com/...]]></description>
		<content:encoded><![CDATA[<p>@Anthony,<br />
Not sure when you checked Discover Card last but when I visit discover.com I am automatically redirected to <a href="https://www.discover.com/" rel="nofollow">https://www.discover.com/</a>&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security Notes &#171; 36 Chambers &#8211; The Legendary Journeys: Execution to the max!</title>
		<link>http://qnrq.se/full-disclosure-american-express/#comment-260</link>
		<dc:creator>Security Notes &#171; 36 Chambers &#8211; The Legendary Journeys: Execution to the max!</dc:creator>
		<pubDate>Fri, 21 Oct 2011 16:05:51 +0000</pubDate>
		<guid isPermaLink="false">http://qnrq.se/?p=91#comment-260</guid>
		<description><![CDATA[[...] via HNTV (and PaulDotCom Security Weekly, where I heard about John and Larry talk about it first), American Express learns that you need to provide security contact information.  Oh, and secure your pages.  The [...]]]></description>
		<content:encoded><![CDATA[<p>[...] via HNTV (and PaulDotCom Security Weekly, where I heard about John and Larry talk about it first), American Express learns that you need to provide security contact information.  Oh, and secure your pages.  The [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Find A Massive Security Hole At American Express? If You&#8217;re Not A Cardholder, It Doesn&#8217;t Care &#171; waweru.net</title>
		<link>http://qnrq.se/full-disclosure-american-express/#comment-175</link>
		<dc:creator>Find A Massive Security Hole At American Express? If You&#8217;re Not A Cardholder, It Doesn&#8217;t Care &#171; waweru.net</dc:creator>
		<pubDate>Wed, 12 Oct 2011 01:38:00 +0000</pubDate>
		<guid isPermaLink="false">http://qnrq.se/?p=91#comment-175</guid>
		<description><![CDATA[[...] Express... and not only not not being able to find anyone to contact, but also being told that the company would pay more attention to him if he were a cardholer:  To my great surprise American Express doesn&#8217;t allow anybody to contact them. Instead, [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Express&#8230; and not only not not being able to find anyone to contact, but also being told that the company would pay more attention to him if he were a cardholer:  To my great surprise American Express doesn&rsquo;t allow anybody to contact them. Instead, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Comwise Internetwork Sdn Bhd &#187; Blog Archive &#187; Developer function enables phishing at American Express</title>
		<link>http://qnrq.se/full-disclosure-american-express/#comment-174</link>
		<dc:creator>Comwise Internetwork Sdn Bhd &#187; Blog Archive &#187; Developer function enables phishing at American Express</dc:creator>
		<pubDate>Wed, 12 Oct 2011 01:02:04 +0000</pubDate>
		<guid isPermaLink="false">http://qnrq.se/?p=91#comment-174</guid>
		<description><![CDATA[[...] specialist Niklas Femerstrand has discovered a hole on theAmerican Express web site that attackers can use to steal, among other things, the login data [...]]]></description>
		<content:encoded><![CDATA[<p>[...] specialist Niklas Femerstrand has discovered a hole on theAmerican Express web site that attackers can use to steal, among other things, the login data [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony</title>
		<link>http://qnrq.se/full-disclosure-american-express/#comment-172</link>
		<dc:creator>Anthony</dc:creator>
		<pubDate>Tue, 11 Oct 2011 23:16:10 +0000</pubDate>
		<guid isPermaLink="false">http://qnrq.se/?p=91#comment-172</guid>
		<description><![CDATA[If you think AmEx&#039;s website is bad, take a look at Discover Card&#039;s.  No SSL on the landing page (and possibly others behind the scenes once you log in).

Oh, and if you need to re-register a replacement card on their site, they are kind enough to email you your existing password as a friendly reminder in CLEARTEXT.  Talk about major FAIL on the part of Discover Financial Services, a bank and one of the U.S.&#039; four major credit card processing companies that developed the Payment Card Industry Data Security Standards... HYPOCRITES!!!]]></description>
		<content:encoded><![CDATA[<p>If you think AmEx&#8217;s website is bad, take a look at Discover Card&#8217;s.  No SSL on the landing page (and possibly others behind the scenes once you log in).</p>
<p>Oh, and if you need to re-register a replacement card on their site, they are kind enough to email you your existing password as a friendly reminder in CLEARTEXT.  Talk about major FAIL on the part of Discover Financial Services, a bank and one of the U.S.&#8217; four major credit card processing companies that developed the Payment Card Industry Data Security Standards&#8230; HYPOCRITES!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Falha de Segurança Compromete Site da American Express &#124; InvasaoHacking.com - Downloads, Video Aulas e Tutoriais sobre Hacker, Trojans, Keyloggers, Worms, Malwares, Virus, phishing, Exploit, Shells, Defacer, banking, carding, Hackear orkut, Hackear Msn, </title>
		<link>http://qnrq.se/full-disclosure-american-express/#comment-170</link>
		<dc:creator>Falha de Segurança Compromete Site da American Express &#124; InvasaoHacking.com - Downloads, Video Aulas e Tutoriais sobre Hacker, Trojans, Keyloggers, Worms, Malwares, Virus, phishing, Exploit, Shells, Defacer, banking, carding, Hackear orkut, Hackear Msn, </dc:creator>
		<pubDate>Tue, 11 Oct 2011 16:30:02 +0000</pubDate>
		<guid isPermaLink="false">http://qnrq.se/?p=91#comment-170</guid>
		<description><![CDATA[[...] Saiba Mais:  [1] 0-Day Full Disclosure American Express http://qnrq.se/full-disclosure-american-express/ [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Saiba Mais:  [1] 0-Day Full Disclosure American Express <a href="http://qnrq.se/full-disclosure-american-express/" rel="nofollow">http://qnrq.se/full-disclosure-american-express/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Межсайтовый скриптинг на сайте American Express &#124; Банкомёт</title>
		<link>http://qnrq.se/full-disclosure-american-express/#comment-167</link>
		<dc:creator>Межсайтовый скриптинг на сайте American Express &#124; Банкомёт</dc:creator>
		<pubDate>Tue, 11 Oct 2011 10:47:37 +0000</pubDate>
		<guid isPermaLink="false">http://qnrq.se/?p=91#comment-167</guid>
		<description><![CDATA[[...]  опубликовал свое &quot;открытие&quot; в среду – в сообщении с POC иллюстрацией [...]]]></description>
		<content:encoded><![CDATA[<p>[...]  опубликовал свое &quot;открытие&quot; в среду – в сообщении с POC иллюстрацией [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
