<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Firefox applet fun</title>
	<atom:link href="http://www.thespanner.co.uk/2008/05/20/210/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2008/05/20/210/</link>
	<description>Javascript blog with messed up syntax inside</description>
	<lastBuildDate>Thu, 26 Jan 2012 01:38:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1238</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 21 May 2008 09:59:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1238</guid>
		<description>@.mario

Thx, I knew about the applet tag insert for a while but I didn&#039;t think it was exploitable. It was good fun to find :D good luck with the conference</description>
		<content:encoded><![CDATA[<p>@.mario</p>
<p>Thx, I knew about the applet tag insert for a while but I didn&#8217;t think it was exploitable. It was good fun to find <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  good luck with the conference</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1237</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Wed, 21 May 2008 09:19:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1237</guid>
		<description>Nice stuff Gareth - finally a &quot;real&quot; XSS again ;) Has been a pretty long time. The issues are fixed in the trunk - 0.4.8 as soon as I return from OWASP Europe.</description>
		<content:encoded><![CDATA[<p>Nice stuff Gareth &#8211; finally a &#8220;real&#8221; XSS again <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Has been a pretty long time. The issues are fixed in the trunk &#8211; 0.4.8 as soon as I return from OWASP Europe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1236</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 20 May 2008 22:16:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1236</guid>
		<description>I&#039;ve tried some code to access data from within this &quot;iframe&quot;, but you&#039;re right so far. &#039;til now I didn&#039;t manage to get around the protection.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve tried some code to access data from within this &#8220;iframe&#8221;, but you&#8217;re right so far. &#8217;til now I didn&#8217;t manage to get around the protection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1234</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 20 May 2008 18:57:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1234</guid>
		<description>@Alex

Yeah I thought that might be possible but it appears that the properties can&#039;t be accessed using &quot;this&quot; and the frames array. However if you can prove me wrong then I&#039;d be very interested on how to do it :)</description>
		<content:encoded><![CDATA[<p>@Alex</p>
<p>Yeah I thought that might be possible but it appears that the properties can&#8217;t be accessed using &#8220;this&#8221; and the frames array. However if you can prove me wrong then I&#8217;d be very interested on how to do it <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1233</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 20 May 2008 18:50:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1233</guid>
		<description>I&#039;ve tested it with the latest FF2. Now it works.
It&#039;s time to try accessing any property or value from outside that &quot;iframe&quot;. Maybe we can bypass the same origin policy and steal userinput from within this &quot;iframe&quot;.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve tested it with the latest FF2. Now it works.<br />
It&#8217;s time to try accessing any property or value from outside that &#8220;iframe&#8221;. Maybe we can bypass the same origin policy and steal userinput from within this &#8220;iframe&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1232</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 20 May 2008 14:50:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1232</guid>
		<description>@Alex

Not tried with beta but it works with latest FF2</description>
		<content:encoded><![CDATA[<p>@Alex</p>
<p>Not tried with beta but it works with latest FF2</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1231</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 20 May 2008 14:47:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1231</guid>
		<description>Which version of Firefox did you use ? I tried it with Firefox 3 RC1 and it didn&#039;t work.</description>
		<content:encoded><![CDATA[<p>Which version of Firefox did you use ? I tried it with Firefox 3 RC1 and it didn&#8217;t work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: daniel</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1230</link>
		<dc:creator>daniel</dc:creator>
		<pubDate>Tue, 20 May 2008 13:37:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1230</guid>
		<description>interesting, damn good find then sir!</description>
		<content:encoded><![CDATA[<p>interesting, damn good find then sir!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1229</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 20 May 2008 12:56:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1229</guid>
		<description>@daniel

I ran a test in strict html and it still seemed to work</description>
		<content:encoded><![CDATA[<p>@daniel</p>
<p>I ran a test in strict html and it still seemed to work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: daniel</title>
		<link>http://www.thespanner.co.uk/2008/05/20/210/#comment-1228</link>
		<dc:creator>daniel</dc:creator>
		<pubDate>Tue, 20 May 2008 12:50:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=210#comment-1228</guid>
		<description>My only issue would be sites that use strict XHTML, this would be rendered useless, no?</description>
		<content:encoded><![CDATA[<p>My only issue would be sites that use strict XHTML, this would be rendered useless, no?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

