<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Firefox applet fun</title>
	<atom:link href="http://www.thespanner.co.uk/2008/05/20/210/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2008/05/20/210/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Thu, 20 Nov 2008 21:18:30 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1238</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 21 May 2008 09:59:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1238</guid>
		<description>@.mario

Thx, I knew about the applet tag insert for a while but I didn't think it was exploitable. It was good fun to find :D good luck with the conference</description>
		<content:encoded><![CDATA[<p>@.mario</p>
<p>Thx, I knew about the applet tag insert for a while but I didn&#8217;t think it was exploitable. It was good fun to find <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> good luck with the conference</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1237</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Wed, 21 May 2008 09:19:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1237</guid>
		<description>Nice stuff Gareth - finally a "real" XSS again ;) Has been a pretty long time. The issues are fixed in the trunk - 0.4.8 as soon as I return from OWASP Europe.</description>
		<content:encoded><![CDATA[<p>Nice stuff Gareth - finally a &#8220;real&#8221; XSS again <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> Has been a pretty long time. The issues are fixed in the trunk - 0.4.8 as soon as I return from OWASP Europe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1236</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 20 May 2008 22:16:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1236</guid>
		<description>I've tried some code to access data from within this "iframe", but you're right so far. 'til now I didn't manage to get around the protection.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve tried some code to access data from within this &#8220;iframe&#8221;, but you&#8217;re right so far. &#8217;til now I didn&#8217;t manage to get around the protection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1234</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 20 May 2008 18:57:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1234</guid>
		<description>@Alex

Yeah I thought that might be possible but it appears that the properties can't be accessed using "this" and the frames array. However if you can prove me wrong then I'd be very interested on how to do it :)</description>
		<content:encoded><![CDATA[<p>@Alex</p>
<p>Yeah I thought that might be possible but it appears that the properties can&#8217;t be accessed using &#8220;this&#8221; and the frames array. However if you can prove me wrong then I&#8217;d be very interested on how to do it <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1233</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 20 May 2008 18:50:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1233</guid>
		<description>I've tested it with the latest FF2. Now it works.
It's time to try accessing any property or value from outside that "iframe". Maybe we can bypass the same origin policy and steal userinput from within this "iframe".</description>
		<content:encoded><![CDATA[<p>I&#8217;ve tested it with the latest FF2. Now it works.<br />
It&#8217;s time to try accessing any property or value from outside that &#8220;iframe&#8221;. Maybe we can bypass the same origin policy and steal userinput from within this &#8220;iframe&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1232</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 20 May 2008 14:50:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1232</guid>
		<description>@Alex

Not tried with beta but it works with latest FF2</description>
		<content:encoded><![CDATA[<p>@Alex</p>
<p>Not tried with beta but it works with latest FF2</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1231</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 20 May 2008 14:47:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1231</guid>
		<description>Which version of Firefox did you use ? I tried it with Firefox 3 RC1 and it didn't work.</description>
		<content:encoded><![CDATA[<p>Which version of Firefox did you use ? I tried it with Firefox 3 RC1 and it didn&#8217;t work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: daniel</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1230</link>
		<dc:creator>daniel</dc:creator>
		<pubDate>Tue, 20 May 2008 13:37:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1230</guid>
		<description>interesting, damn good find then sir!</description>
		<content:encoded><![CDATA[<p>interesting, damn good find then sir!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1229</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 20 May 2008 12:56:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1229</guid>
		<description>@daniel

I ran a test in strict html and it still seemed to work</description>
		<content:encoded><![CDATA[<p>@daniel</p>
<p>I ran a test in strict html and it still seemed to work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: daniel</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1228</link>
		<dc:creator>daniel</dc:creator>
		<pubDate>Tue, 20 May 2008 12:50:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1228</guid>
		<description>My only issue would be sites that use strict XHTML, this would be rendered useless, no?</description>
		<content:encoded><![CDATA[<p>My only issue would be sites that use strict XHTML, this would be rendered useless, no?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
