<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Moz-binding XSS fun</title>
	<atom:link href="http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Tue, 14 Oct 2008 02:00:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Vinicius K-Max</title>
		<link>http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1121</link>
		<dc:creator>Vinicius K-Max</dc:creator>
		<pubDate>Wed, 06 Feb 2008 01:57:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1121</guid>
		<description>awesome! :)</description>
		<content:encoded><![CDATA[<p>awesome! <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1119</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 05 Feb 2008 09:26:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1119</guid>
		<description>@riahmatic 

Yep that's the expected behavior but FF2 seems to read the entities first and decode them but for some reason only takes into account the first few characters (maybe because it's in a style).

I've not looked at FF3 yet much but I'm sure to have plenty of fun when I do :) If FF3 does enforce SOP on moz-binding then that's a good thing but I've not seen it mentioned anywhere.</description>
		<content:encoded><![CDATA[<p>@riahmatic </p>
<p>Yep that&#8217;s the expected behavior but FF2 seems to read the entities first and decode them but for some reason only takes into account the first few characters (maybe because it&#8217;s in a style).</p>
<p>I&#8217;ve not looked at FF3 yet much but I&#8217;m sure to have plenty of fun when I do <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> If FF3 does enforce SOP on moz-binding then that&#8217;s a good thing but I&#8217;ve not seen it mentioned anywhere.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: riahmatic</title>
		<link>http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1118</link>
		<dc:creator>riahmatic</dc:creator>
		<pubDate>Tue, 05 Feb 2008 04:07:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1118</guid>
		<description>error console in FF3:
Warning: Unknown property '尭屭屯屺尭屢屩屮層屩屮屧'.  Declaration dropped.

Though I think FF3 enforces SOP on -moz-binding now anyway, right?</description>
		<content:encoded><![CDATA[<p>error console in FF3:<br />
Warning: Unknown property &#8216;尭屭屯屺尭屢屩屮層屩屮屧&#8217;.  Declaration dropped.</p>
<p>Though I think FF3 enforces SOP on -moz-binding now anyway, right?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1116</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 04 Feb 2008 15:24:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1116</guid>
		<description>Another thing I forgot to mention is that noscript silently disables moz-binding, so you have to disable noscript to test the vector.</description>
		<content:encoded><![CDATA[<p>Another thing I forgot to mention is that noscript silently disables moz-binding, so you have to disable noscript to test the vector.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1115</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 04 Feb 2008 15:21:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1115</guid>
		<description>Yep only tested in Firefox 2, although other tricks may be possible with FF3, I might have a go at that some other time :)</description>
		<content:encoded><![CDATA[<p>Yep only tested in Firefox 2, although other tricks may be possible with FF3, I might have a go at that some other time <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1114</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 04 Feb 2008 14:55:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2008/02/04/moz-binding-xss-fun/#comment-1114</guid>
		<description>interesting, I quickly checked the method in Firefox 3 and it doesn't seem to work. I haven't checked it in Firefox 2 though.</description>
		<content:encoded><![CDATA[<p>interesting, I quickly checked the method in Firefox 3 and it doesn&#8217;t seem to work. I haven&#8217;t checked it in Firefox 2 though.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
