<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Firefox weird javascript execution</title>
	<atom:link href="http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Thu, 20 Nov 2008 21:26:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-395</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 16 Aug 2007 19:56:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-395</guid>
		<description>Hmmmm interesting Brad thanks I didn't know that.</description>
		<content:encoded><![CDATA[<p>Hmmmm interesting Brad thanks I didn&#8217;t know that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Shuttleworth</title>
		<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-394</link>
		<dc:creator>Brad Shuttleworth</dc:creator>
		<pubDate>Thu, 16 Aug 2007 19:02:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-394</guid>
		<description>Actually - that first one is a valid HREF in terms of the rfcs - means "use the same scheme as this location, but change the other options".  

Mucked me around when I ran into it while writing a rewriting-proxy... you can see it used on slashdot.org's links.</description>
		<content:encoded><![CDATA[<p>Actually - that first one is a valid HREF in terms of the rfcs - means &#8220;use the same scheme as this location, but change the other options&#8221;.  </p>
<p>Mucked me around when I ran into it while writing a rewriting-proxy&#8230; you can see it used on slashdot.org&#8217;s links.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-369</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 14 Aug 2007 08:44:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-369</guid>
		<description>I'd just like to say that the PHPIDS protects against even the attack mentioned in the post. Which I found quite impressive, the project is open source and they're not paying me to say they're good either honest but I'll give credit were credit is due and criticism were criticism is due, you know me ;)
&lt;a href="http://php-ids.org/" rel="nofollow"&gt;Get involved with their project&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>I&#8217;d just like to say that the PHPIDS protects against even the attack mentioned in the post. Which I found quite impressive, the project is open source and they&#8217;re not paying me to say they&#8217;re good either honest but I&#8217;ll give credit were credit is due and criticism were criticism is due, you know me <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
<a href="http://php-ids.org/" rel="nofollow">Get involved with their project</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lars Gunther</title>
		<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-368</link>
		<dc:creator>Lars Gunther</dc:creator>
		<pubDate>Tue, 14 Aug 2007 01:02:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-368</guid>
		<description>It looks like Firefox is actually honoring the SGML parsing rules! Weird for the average user and totally unusable. Thank goodness HTML 5 will remove the pretense that HTML is an SGML application.</description>
		<content:encoded><![CDATA[<p>It looks like Firefox is actually honoring the SGML parsing rules! Weird for the average user and totally unusable. Thank goodness HTML 5 will remove the pretense that HTML is an SGML application.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-366</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 13 Aug 2007 20:49:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-366</guid>
		<description>Steve yeah there's some strange stuff with commenting too, Firefox doesn't handle comments correctly and IE renders some pretty insane stuff too.

The browsers should all adopt a strict standard which doesn't allow this rubbish to get through because it's only a matter of time before the next Myspace/Wordpress/Enter any site here worm gets loose on the internet.</description>
		<content:encoded><![CDATA[<p>Steve yeah there&#8217;s some strange stuff with commenting too, Firefox doesn&#8217;t handle comments correctly and IE renders some pretty insane stuff too.</p>
<p>The browsers should all adopt a strict standard which doesn&#8217;t allow this rubbish to get through because it&#8217;s only a matter of time before the next Myspace/Wordpress/Enter any site here worm gets loose on the internet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-365</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 13 Aug 2007 20:46:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-365</guid>
		<description>Whitelisting is the only way to go Ronald, there's just so much that is possible. I think although you can be clever with RegExps someday you'll get burned.</description>
		<content:encoded><![CDATA[<p>Whitelisting is the only way to go Ronald, there&#8217;s just so much that is possible. I think although you can be clever with RegExps someday you&#8217;ll get burned.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-363</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Mon, 13 Aug 2007 20:28:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-363</guid>
		<description>Definately strange... when you consider what the double slash in JavaScript terms is...

&#60;a href="javascript:doThis();//dontDoThis();"&#62;Click me&#60;/a&#62;

doThis should run, dontDoThis is commented out...

Glad to hear this doesn't work on IE though... or I'm sure there would be a horrid script on the loose. ;-)</description>
		<content:encoded><![CDATA[<p>Definately strange&#8230; when you consider what the double slash in JavaScript terms is&#8230;</p>
<p>&lt;a href=&#8221;javascript:doThis();//dontDoThis();&#8221;&gt;Click me&lt;/a&gt;</p>
<p>doThis should run, dontDoThis is commented out&#8230;</p>
<p>Glad to hear this doesn&#8217;t work on IE though&#8230; or I&#8217;m sure there would be a horrid script on the loose. <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronald van den Heetk</title>
		<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-362</link>
		<dc:creator>Ronald van den Heetk</dc:creator>
		<pubDate>Mon, 13 Aug 2007 20:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-362</guid>
		<description>Hi Gareth,

Yes they help out a lot of sloppy coders, they've managed to write some insanely good RegExes to interpret what you mean by writing that gibberish. Incredible isn't it? I've had a couple of vectors myself that were just mind blowing and still worked. I think we all can agree on whitelisting now! ;)</description>
		<content:encoded><![CDATA[<p>Hi Gareth,</p>
<p>Yes they help out a lot of sloppy coders, they&#8217;ve managed to write some insanely good RegExes to interpret what you mean by writing that gibberish. Incredible isn&#8217;t it? I&#8217;ve had a couple of vectors myself that were just mind blowing and still worked. I think we all can agree on whitelisting now! <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-361</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 13 Aug 2007 19:47:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-361</guid>
		<description>Hi Steve

No you read incorrectly I support syntax colouring but nice try lol.

&lt;pre lang="php"&gt;
&lt;?php
echo 'example';
?&gt;
&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>Hi Steve</p>
<p>No you read incorrectly I support syntax colouring but nice try lol.</p>

<div class="wp_syntax"><div class="code"><pre class="php php" style="font-family:monospace;"><span style="color: #000000; font-weight: bold;">&lt;?php</span>
<span style="color: #990000;">echo</span> <span style="">'example'</span>;
<span style="color: #000000; font-weight: bold;">?&gt;</span></pre></div></div>

]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-360</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Mon, 13 Aug 2007 18:52:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/13/firefox-weird-javascript-execution/#comment-360</guid>
		<description>Interesting...

Just reading your message options... do I read correctly that you support JavaScript in the comments?... this sounds dangerous...

alert('Script should not be allowed in comments.');

cheers
steve</description>
		<content:encoded><![CDATA[<p>Interesting&#8230;</p>
<p>Just reading your message options&#8230; do I read correctly that you support JavaScript in the comments?&#8230; this sounds dangerous&#8230;</p>
<p>alert(&#8217;Script should not be allowed in comments.&#8217;);</p>
<p>cheers<br />
steve</p>
]]></content:encoded>
	</item>
</channel>
</rss>
