<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Safari security</title>
	<atom:link href="http://www.thespanner.co.uk/2007/11/16/safari-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/11/16/safari-security/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Fri, 25 Jul 2008 14:10:05 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-856</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 16 Nov 2007 23:31:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-856</guid>
		<description>Well it opens a terminal window and an attacker can send data to that terminal window without the user doing anything. Did I say this was a really dangerous flaw? 

All I'm saying is that it shouldn't be possible for an attacker to display a terminal window and send data to it because some users may provide data that they shouldn't.

I'm not hear to debate the seriousness of the flaw, I couldn't care less I just enjoy finding unusual flaws. Discussion closed.</description>
		<content:encoded><![CDATA[<p>Well it opens a terminal window and an attacker can send data to that terminal window without the user doing anything. Did I say this was a really dangerous flaw? </p>
<p>All I&#8217;m saying is that it shouldn&#8217;t be possible for an attacker to display a terminal window and send data to it because some users may provide data that they shouldn&#8217;t.</p>
<p>I&#8217;m not hear to debate the seriousness of the flaw, I couldn&#8217;t care less I just enjoy finding unusual flaws. Discussion closed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fnord</title>
		<link>http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-855</link>
		<dc:creator>fnord</dc:creator>
		<pubDate>Fri, 16 Nov 2007 23:22:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-855</guid>
		<description>You can receive data from a server, true. But it neither get saved on client side nor is there any execution (beside the start of a telnet session). 

I don't see how the telnet client sends data to the server *without user interaction*. Every JS execution is far more dangerous than that.</description>
		<content:encoded><![CDATA[<p>You can receive data from a server, true. But it neither get saved on client side nor is there any execution (beside the start of a telnet session). </p>
<p>I don&#8217;t see how the telnet client sends data to the server *without user interaction*. Every JS execution is far more dangerous than that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-854</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 16 Nov 2007 19:54:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-854</guid>
		<description>Erm no it's not because the attacker can send and receive information to the user without confirmation.</description>
		<content:encoded><![CDATA[<p>Erm no it&#8217;s not because the attacker can send and receive information to the user without confirmation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fnord</title>
		<link>http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-853</link>
		<dc:creator>fnord</dc:creator>
		<pubDate>Fri, 16 Nov 2007 19:14:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-853</guid>
		<description>Well, this is the same as if you use prefixes like aim:// or xmpp: and such. As long as you cannot get any execution or overwriting of files like the telnet://-nFile bug it's completly useless for exploitation or phishing. I bet you don't get one single person to type in a password that way. 

I personally don't think that telnet needs to be handled that way in browsers at all, but it's definitely not a critical bug.</description>
		<content:encoded><![CDATA[<p>Well, this is the same as if you use prefixes like aim:// or xmpp: and such. As long as you cannot get any execution or overwriting of files like the <a href="telnet://-nFile" rel="nofollow">telnet://-nFile</a> bug it&#8217;s completly useless for exploitation or phishing. I bet you don&#8217;t get one single person to type in a password that way. </p>
<p>I personally don&#8217;t think that telnet needs to be handled that way in browsers at all, but it&#8217;s definitely not a critical bug.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcin</title>
		<link>http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-852</link>
		<dc:creator>Marcin</dc:creator>
		<pubDate>Fri, 16 Nov 2007 17:42:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-852</guid>
		<description>Haha, I love the remedy you prescribe. Good one! :)</description>
		<content:encoded><![CDATA[<p>Haha, I love the remedy you prescribe. Good one! <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-851</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 16 Nov 2007 16:24:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-851</guid>
		<description>Cheers :) it ain't gonna stop there. I hold a grudge :)</description>
		<content:encoded><![CDATA[<p>Cheers <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> it ain&#8217;t gonna stop there. I hold a grudge <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: thorin</title>
		<link>http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-850</link>
		<dc:creator>thorin</dc:creator>
		<pubDate>Fri, 16 Nov 2007 16:19:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-850</guid>
		<description>Nice find Gareth.</description>
		<content:encoded><![CDATA[<p>Nice find Gareth.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-847</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 16 Nov 2007 14:13:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-847</guid>
		<description>It's pretty bad for phishing as it stands because it could prompt for the OS X password for example but I might find some more stuff in future because Apple has released a new update of Safari :)</description>
		<content:encoded><![CDATA[<p>It&#8217;s pretty bad for phishing as it stands because it could prompt for the OS X password for example but I might find some more stuff in future because Apple has released a new update of Safari <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-846</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 16 Nov 2007 13:43:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-846</guid>
		<description>interesting, though I am not sure about the impact of this issue, unless you can pass commands to the telnet client.</description>
		<content:encoded><![CDATA[<p>interesting, though I am not sure about the impact of this issue, unless you can pass commands to the telnet client.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-845</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 16 Nov 2007 12:47:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/16/safari-security/#comment-845</guid>
		<description>Yeah but Apple should at least prompt the connection on telnet. I mean geez you can connect to any local/web address.</description>
		<content:encoded><![CDATA[<p>Yeah but Apple should at least prompt the connection on telnet. I mean geez you can connect to any local/web address.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
