<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Thank you and good night Planet PHP</title>
	<atom:link href="http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Tue, 14 Oct 2008 01:45:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Tom Macklin</title>
		<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-554</link>
		<dc:creator>Tom Macklin</dc:creator>
		<pubDate>Fri, 07 Sep 2007 12:39:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-554</guid>
		<description>Dave-

Of course I wouldn't have spotted the problems with that vulnerability without careful investigation, if ever!  In security, people often have their own technique for finding particular types of problems.  Also, just because I strive to write correct software doesn't mean I do it.  However, we do have a responsibility to ensure our software does what we claim it does, and most software products claim to be secure.

BTW- I don't intend to get involved in a flame war that clogs up this blog... good luck doing your thing.</description>
		<content:encoded><![CDATA[<p>Dave-</p>
<p>Of course I wouldn&#8217;t have spotted the problems with that vulnerability without careful investigation, if ever!  In security, people often have their own technique for finding particular types of problems.  Also, just because I strive to write correct software doesn&#8217;t mean I do it.  However, we do have a responsibility to ensure our software does what we claim it does, and most software products claim to be secure.</p>
<p>BTW- I don&#8217;t intend to get involved in a flame war that clogs up this blog&#8230; good luck doing your thing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-553</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 07 Sep 2007 12:31:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-553</guid>
		<description>Thanks Tom much appreciated, I always blog about the stuff I'm passionate about and that's why I find it easy to do, you're right it's not for everyone but I'm not trying to appeal to everyone, I just want to share knowledge and talk to clever people.

In the last few months I've talked to some outstanding programmers and starting blogging was probably one of the best decisions I've made.</description>
		<content:encoded><![CDATA[<p>Thanks Tom much appreciated, I always blog about the stuff I&#8217;m passionate about and that&#8217;s why I find it easy to do, you&#8217;re right it&#8217;s not for everyone but I&#8217;m not trying to appeal to everyone, I just want to share knowledge and talk to clever people.</p>
<p>In the last few months I&#8217;ve talked to some outstanding programmers and starting blogging was probably one of the best decisions I&#8217;ve made.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Macklin</title>
		<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-552</link>
		<dc:creator>Tom Macklin</dc:creator>
		<pubDate>Fri, 07 Sep 2007 12:19:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-552</guid>
		<description>Gareth-  I never have gotten around to saying "thanks" for such an *informative* blog.  Most blogs seem to focus on sound bytes-- I think this one focuses on, well, focused substance.  Not for everyone, but great for those it is for.</description>
		<content:encoded><![CDATA[<p>Gareth-  I never have gotten around to saying &#8220;thanks&#8221; for such an *informative* blog.  Most blogs seem to focus on sound bytes&#8211; I think this one focuses on, well, focused substance.  Not for everyone, but great for those it is for.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-551</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 07 Sep 2007 10:55:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-551</guid>
		<description>Richard thanks a lot, it helps a great deal if I know people are learning or enjoy my posts.</description>
		<content:encoded><![CDATA[<p>Richard thanks a lot, it helps a great deal if I know people are learning or enjoy my posts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Fletcher</title>
		<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-550</link>
		<dc:creator>Richard Fletcher</dc:creator>
		<pubDate>Fri, 07 Sep 2007 10:51:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-550</guid>
		<description>Hi Gareth, 

I've been educated and entertained by your posts, and will be subscribing to your own feed. 

Thanks for sharing your work.

Regards
Richard</description>
		<content:encoded><![CDATA[<p>Hi Gareth, </p>
<p>I&#8217;ve been educated and entertained by your posts, and will be subscribing to your own feed. </p>
<p>Thanks for sharing your work.</p>
<p>Regards<br />
Richard</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-541</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 06 Sep 2007 21:04:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-541</guid>
		<description>Well every browser should deny access to write access things like the document object. Firefox's behavior in this matter is the best. 

But this specific vulnerability is the way Safari handles local files, it seems that if a file is run locally or fooled into thinking it is local then the cross domain policy seems to go out the window. Hence why I could access data from other domains.

I would recommend everyone uses an alternate browser until Apple release a fix for the beta as this vulnerability is extremely dangerous, it would be possible to hide the iframe and perform any action on any web site and retrieve data as that person. 

Normally I would have reported this to the manufacturer before releasing it to the public but Apple's attitude deserved otherwise.</description>
		<content:encoded><![CDATA[<p>Well every browser should deny access to write access things like the document object. Firefox&#8217;s behavior in this matter is the best. </p>
<p>But this specific vulnerability is the way Safari handles local files, it seems that if a file is run locally or fooled into thinking it is local then the cross domain policy seems to go out the window. Hence why I could access data from other domains.</p>
<p>I would recommend everyone uses an alternate browser until Apple release a fix for the beta as this vulnerability is extremely dangerous, it would be possible to hide the iframe and perform any action on any web site and retrieve data as that person. </p>
<p>Normally I would have reported this to the manufacturer before releasing it to the public but Apple&#8217;s attitude deserved otherwise.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Rodger</title>
		<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-540</link>
		<dc:creator>David Rodger</dc:creator>
		<pubDate>Thu, 06 Sep 2007 20:45:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-540</guid>
		<description>Maybe it's just Safari, Tom, but I don't see a mechanism for indicating that your reply is to a specific post (unlike, say, Serendipity on Stefan Esser's site).

&#62;If you want it to work, then write correct code.

Tom, do you write code for the web, where this vulnerability and its consequences would become evident? If you're not a "web type", I'm impressed that would have spotted it in a nano-second (as opposed to the long, hard slog Gareth put in to find it). Incidentally, what is it of yours that is bad?

Gareth, could you tell us whether you think what the Safari beta does is what it (or any browser, for that matter) ought to do?</description>
		<content:encoded><![CDATA[<p>Maybe it&#8217;s just Safari, Tom, but I don&#8217;t see a mechanism for indicating that your reply is to a specific post (unlike, say, Serendipity on Stefan Esser&#8217;s site).</p>
<p>&gt;If you want it to work, then write correct code.</p>
<p>Tom, do you write code for the web, where this vulnerability and its consequences would become evident? If you&#8217;re not a &#8220;web type&#8221;, I&#8217;m impressed that would have spotted it in a nano-second (as opposed to the long, hard slog Gareth put in to find it). Incidentally, what is it of yours that is bad?</p>
<p>Gareth, could you tell us whether you think what the Safari beta does is what it (or any browser, for that matter) ought to do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Macklin</title>
		<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-539</link>
		<dc:creator>Tom Macklin</dc:creator>
		<pubDate>Thu, 06 Sep 2007 17:21:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-539</guid>
		<description>That last comment was supposed to be a reply just to David Roger comment (#18), but it showed up as a comment on the whole article... my bad.</description>
		<content:encoded><![CDATA[<p>That last comment was supposed to be a reply just to David Roger comment (#18), but it showed up as a comment on the whole article&#8230; my bad.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Macklin</title>
		<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-538</link>
		<dc:creator>Tom Macklin</dc:creator>
		<pubDate>Thu, 06 Sep 2007 17:20:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-538</guid>
		<description>The reason I hate coding w/ web-types most of the time is this attitude "of I just want it to work."  If you want it to work, then write correct code.  The trouble is, you don't "just want it to work"-- you want to get a lot of result w/o much effort or thought.

I'd check out a different career field.</description>
		<content:encoded><![CDATA[<p>The reason I hate coding w/ web-types most of the time is this attitude &#8220;of I just want it to work.&#8221;  If you want it to work, then write correct code.  The trouble is, you don&#8217;t &#8220;just want it to work&#8221;&#8211; you want to get a lot of result w/o much effort or thought.</p>
<p>I&#8217;d check out a different career field.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-531</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 06 Sep 2007 11:56:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/05/thank-you-and-good-night-planet-php/#comment-531</guid>
		<description>I haven't tagged my latest post about window.name vulnerability with PHP, so it won't appear on PHP Planet. Even though that knowledge is needed by PHP developers because the very example is used for a PHPIDS system. They are trying to filter out javascript injection.

But hey it's not PHP related eh? See how silly some people are.</description>
		<content:encoded><![CDATA[<p>I haven&#8217;t tagged my latest post about window.name vulnerability with PHP, so it won&#8217;t appear on PHP Planet. Even though that knowledge is needed by PHP developers because the very example is used for a PHPIDS system. They are trying to filter out javascript injection.</p>
<p>But hey it&#8217;s not PHP related eh? See how silly some people are.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
