<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Safari beta zero day</title>
	<atom:link href="http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Fri, 25 Jul 2008 14:40:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-656</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sat, 06 Oct 2007 23:01:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-656</guid>
		<description>Luke I'm not sure if Firefox 2.0.0.7 is vulnerable, the POC should display an alert box with the source and cookies from the Amazon domain, when I tired it in Firefox this did not work.</description>
		<content:encoded><![CDATA[<p>Luke I&#8217;m not sure if Firefox 2.0.0.7 is vulnerable, the POC should display an alert box with the source and cookies from the Amazon domain, when I tired it in Firefox this did not work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: luke</title>
		<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-655</link>
		<dc:creator>luke</dc:creator>
		<pubDate>Sat, 06 Oct 2007 19:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-655</guid>
		<description>Firefox 2.0.0.7 is also vulnerable</description>
		<content:encoded><![CDATA[<p>Firefox 2.0.0.7 is also vulnerable</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: thorin</title>
		<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-644</link>
		<dc:creator>thorin</dc:creator>
		<pubDate>Wed, 03 Oct 2007 12:50:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-644</guid>
		<description>@Wez

It's not that they said it wasn't a bug it's that they said it wasn't a security issue.</description>
		<content:encoded><![CDATA[<p>@Wez</p>
<p>It&#8217;s not that they said it wasn&#8217;t a bug it&#8217;s that they said it wasn&#8217;t a security issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wez Furlong</title>
		<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-409</link>
		<dc:creator>Wez Furlong</dc:creator>
		<pubDate>Fri, 17 Aug 2007 18:57:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-409</guid>
		<description>and perhaps I should clean my glasses, because I missed the part where apple said it wasn't a bug...
Ignore my previous comment :)</description>
		<content:encoded><![CDATA[<p>and perhaps I should clean my glasses, because I missed the part where apple said it wasn&#8217;t a bug&#8230;<br />
Ignore my previous comment <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wez Furlong</title>
		<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-408</link>
		<dc:creator>Wez Furlong</dc:creator>
		<pubDate>Fri, 17 Aug 2007 18:53:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-408</guid>
		<description>With software products that are shipped to the end-user, beta status means that there are problems, known or otherwise and the beta tester expects to run into problems, and expects to have to wait for a new beta release to correct them, even if they are super critical bugs.

It's great that you filed a bug, but you can't expect fixes in beta releases on your schedule.

When they go gold, it had better be fixed, of course.  But until then, you need to set your expectations correctly--and it I think that you can blame Web2.0 perpetual beta services for your misconception about beta software products.</description>
		<content:encoded><![CDATA[<p>With software products that are shipped to the end-user, beta status means that there are problems, known or otherwise and the beta tester expects to run into problems, and expects to have to wait for a new beta release to correct them, even if they are super critical bugs.</p>
<p>It&#8217;s great that you filed a bug, but you can&#8217;t expect fixes in beta releases on your schedule.</p>
<p>When they go gold, it had better be fixed, of course.  But until then, you need to set your expectations correctly&#8211;and it I think that you can blame Web2.0 perpetual beta services for your misconception about beta software products.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronald</title>
		<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-407</link>
		<dc:creator>Ronald</dc:creator>
		<pubDate>Fri, 17 Aug 2007 17:03:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-407</guid>
		<description>BTW: MSIE did have it, but they disabled it in MSIE 7, which was a wise choice. And yes Mozilla is walking behind the facts again.</description>
		<content:encoded><![CDATA[<p>BTW: MSIE did have it, but they disabled it in MSIE 7, which was a wise choice. And yes Mozilla is walking behind the facts again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronald</title>
		<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-406</link>
		<dc:creator>Ronald</dc:creator>
		<pubDate>Fri, 17 Aug 2007 16:58:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-406</guid>
		<description>No it's Netscape only (strictly)  I'm sure some freaks have ported it, but that's not the point.

Well, it's tough to read it remotely, but I figured it might divert some filters in Mozilla when I was playing with the chrome. I can access certain sensitive files in Firefox, like preferences but Now I need to figure out how to catch the stuff. 

Still is, it works locally. And you don't need any privileges to read stuff. So it could be used to read files where you would not have access.</description>
		<content:encoded><![CDATA[<p>No it&#8217;s Netscape only (strictly)  I&#8217;m sure some freaks have ported it, but that&#8217;s not the point.</p>
<p>Well, it&#8217;s tough to read it remotely, but I figured it might divert some filters in Mozilla when I was playing with the chrome. I can access certain sensitive files in Firefox, like preferences but Now I need to figure out how to catch the stuff. </p>
<p>Still is, it works locally. And you don&#8217;t need any privileges to read stuff. So it could be used to read files where you would not have access.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-405</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 17 Aug 2007 13:55:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-405</guid>
		<description>It doesn't work in Safari, it seems to be a Firefox feature. Lol if you're browsing as root then you deserve everything you get :)

Yep I think there is scope for a problem with Firefox, I'd watch Ronald's blog for updates.</description>
		<content:encoded><![CDATA[<p>It doesn&#8217;t work in Safari, it seems to be a Firefox feature. Lol if you&#8217;re browsing as root then you deserve everything you get <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Yep I think there is scope for a problem with Firefox, I&#8217;d watch Ronald&#8217;s blog for updates.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kae Verens</title>
		<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-404</link>
		<dc:creator>Kae Verens</dc:creator>
		<pubDate>Fri, 17 Aug 2007 13:36:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-404</guid>
		<description>interesting... in Linux, Firefox (haven't got Safari) try this:
view-source:file:///etc/passwd

or if you're root, 
view-source:file:///etc/shadow
(of course, no-one would ever browse as root ;-) )</description>
		<content:encoded><![CDATA[<p>interesting&#8230; in Linux, Firefox (haven&#8217;t got Safari) try this:<br />
view-source:file:///etc/passwd</p>
<p>or if you&#8217;re root,<br />
view-source:file:///etc/shadow<br />
(of course, no-one would ever browse as root <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> )</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-403</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 17 Aug 2007 13:04:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/17/safari-beta-zero-day/#comment-403</guid>
		<description>I'm sure there's something to that:-
view-source:chrome://global/locale/config.dtd

But you would have to access the xml from the iframe in order to use it.</description>
		<content:encoded><![CDATA[<p>I&#8217;m sure there&#8217;s something to that:-<br />
view-source:chrome://global/locale/config.dtd</p>
<p>But you would have to access the xml from the iframe in order to use it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
