<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: CSS LAN scanner</title>
	<atom:link href="http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Tue, 30 Sep 2008 23:43:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: tiffany</title>
		<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-1310</link>
		<dc:creator>tiffany</dc:creator>
		<pubDate>Sun, 14 Sep 2008 05:42:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-1310</guid>
		<description>i have something to ask: 
what if the 2 IP NOS IS SAME on the e mail , does it mean the same person using the same acc ?</description>
		<content:encoded><![CDATA[<p>i have something to ask:<br />
what if the 2 IP NOS IS SAME on the e mail , does it mean the same person using the same acc ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-526</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 06 Sep 2007 10:23:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-526</guid>
		<description>Some of you may have experienced some problems storing the IP address on Firefox. I have found the problem happens when the user agent hasn't been set for the browser. 

This is because the security filters on my site, so the scanner will work in Firefox on all platforms.</description>
		<content:encoded><![CDATA[<p>Some of you may have experienced some problems storing the IP address on Firefox. I have found the problem happens when the user agent hasn&#8217;t been set for the browser. </p>
<p>This is because the security filters on my site, so the scanner will work in Firefox on all platforms.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-472</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 31 Aug 2007 08:18:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-472</guid>
		<description>Hi Unomi

If you mean as a protection against LAN scanning then I don't think it would be make any difference unfortunately because if you reset all visited states, the scanner then creates a new set of history so therefore overwriting the rule.

The only way I could think to protect against this sort of attack would be to use something like stylish to disable the visited state altogether so the site in question cannot access the visited selector.</description>
		<content:encoded><![CDATA[<p>Hi Unomi</p>
<p>If you mean as a protection against LAN scanning then I don&#8217;t think it would be make any difference unfortunately because if you reset all visited states, the scanner then creates a new set of history so therefore overwriting the rule.</p>
<p>The only way I could think to protect against this sort of attack would be to use something like stylish to disable the visited state altogether so the site in question cannot access the visited selector.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unomi</title>
		<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-471</link>
		<dc:creator>Unomi</dc:creator>
		<pubDate>Fri, 31 Aug 2007 08:10:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-471</guid>
		<description>One more comment/question....

CSS allows to overrule previous set definitions. Isn't it possible to overrule any 'visited' property with a default value? This way the url shouldn't be requested.

Or am I wrong?

- Unomi -</description>
		<content:encoded><![CDATA[<p>One more comment/question&#8230;.</p>
<p>CSS allows to overrule previous set definitions. Isn&#8217;t it possible to overrule any &#8216;visited&#8217; property with a default value? This way the url shouldn&#8217;t be requested.</p>
<p>Or am I wrong?</p>
<p>- Unomi -</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-455</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 28 Aug 2007 14:22:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-455</guid>
		<description>I realise that this does leave Firefox and probably other browsers open to attack but I'm sick and tired of communicating with manufacturers who seem to think they know better than me and dismiss my reports.

I've also had enough with the biased media coverage of security blogs to the point now were I don't even care. It is laughable that this article will never get coverage so I'm leaving up to the manufacturers to monitor my web site because why should I go to all the effort for nothing?</description>
		<content:encoded><![CDATA[<p>I realise that this does leave Firefox and probably other browsers open to attack but I&#8217;m sick and tired of communicating with manufacturers who seem to think they know better than me and dismiss my reports.</p>
<p>I&#8217;ve also had enough with the biased media coverage of security blogs to the point now were I don&#8217;t even care. It is laughable that this article will never get coverage so I&#8217;m leaving up to the manufacturers to monitor my web site because why should I go to all the effort for nothing?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-454</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 28 Aug 2007 14:16:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-454</guid>
		<description>Cleaning your history will do no good for CSS LAN scanning because the script actually creates the history on page load, therefore the only protection is to disable visited in CSS.

Yes any url that can be opened by iframes is available to be exploited.</description>
		<content:encoded><![CDATA[<p>Cleaning your history will do no good for CSS LAN scanning because the script actually creates the history on page load, therefore the only protection is to disable visited in CSS.</p>
<p>Yes any url that can be opened by iframes is available to be exploited.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unomi</title>
		<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-453</link>
		<dc:creator>Unomi</dc:creator>
		<pubDate>Tue, 28 Aug 2007 14:05:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-453</guid>
		<description>This is only based on the browsers history. What if one cleans the history every minute?

Is every browser vulnerable?

BTW, this attack is not limited to HTTP requests. Any request to a URL supported by a browser can be logged. Say, FTP (ftp://), or port numbers (http://localhost:8080/) can be logged without notice.

Awesome if you want to exploit it, a nightmare if you want to prevent it.

- Unomi -</description>
		<content:encoded><![CDATA[<p>This is only based on the browsers history. What if one cleans the history every minute?</p>
<p>Is every browser vulnerable?</p>
<p>BTW, this attack is not limited to HTTP requests. Any request to a URL supported by a browser can be logged. Say, FTP (ftp://), or port numbers (http://localhost:8080/) can be logged without notice.</p>
<p>Awesome if you want to exploit it, a nightmare if you want to prevent it.</p>
<p>- Unomi -</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-452</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 28 Aug 2007 14:00:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-452</guid>
		<description>Yep in the last few years the browser manufacturers have been very lazy regarding new security policies. 

I'm just looking at the Firefox CSS features now and I can see huge scope for security problems, when I release the CSK (CSS Scripting Kit) you'll see some of the issues.

Web security is certainly a myth, time they got their act together!</description>
		<content:encoded><![CDATA[<p>Yep in the last few years the browser manufacturers have been very lazy regarding new security policies. </p>
<p>I&#8217;m just looking at the Firefox CSS features now and I can see huge scope for security problems, when I release the CSK (CSS Scripting Kit) you&#8217;ll see some of the issues.</p>
<p>Web security is certainly a myth, time they got their act together!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronald</title>
		<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-451</link>
		<dc:creator>Ronald</dc:creator>
		<pubDate>Tue, 28 Aug 2007 13:28:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-451</guid>
		<description>Let's call the web deceased shall we?, or at least websecurity is a myth. ;)</description>
		<content:encoded><![CDATA[<p>Let&#8217;s call the web deceased shall we?, or at least websecurity is a myth. <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-450</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 28 Aug 2007 08:39:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/08/24/css-lan-scanner/#comment-450</guid>
		<description>Yep I know what you mean *some* will know what you can do with it and *some* will not ;)</description>
		<content:encoded><![CDATA[<p>Yep I know what you mean *some* will know what you can do with it and *some* will not <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
</channel>
</rss>
