<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Javascript protocol fuzz results</title>
	<atom:link href="http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Thu, 20 Nov 2008 22:26:55 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Abeon Tech</title>
		<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/#comment-1334</link>
		<dc:creator>Abeon Tech</dc:creator>
		<pubDate>Thu, 16 Oct 2008 11:56:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=215#comment-1334</guid>
		<description>Seems like they are opening more holes in each release......

Why don't some people ever learn :D</description>
		<content:encoded><![CDATA[<p>Seems like they are opening more holes in each release&#8230;&#8230;</p>
<p>Why don&#8217;t some people ever learn <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/#comment-1315</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 18 Sep 2008 08:23:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=215#comment-1315</guid>
		<description>Opera now has more :D in the latest version:-
http://www.thespanner.co.uk/2008/09/18/javascript-protocol-fuzzer-and-opera/</description>
		<content:encoded><![CDATA[<p>Opera now has more <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> in the latest version:-<br />
<a href="http://www.thespanner.co.uk/2008/09/18/javascript-protocol-fuzzer-and-opera/" rel="nofollow">http://www.thespanner.co.uk/2008/09/18/javascript-protocol-fuzzer-and-opera/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/#comment-1314</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 18 Sep 2008 07:48:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=215#comment-1314</guid>
		<description>And as if by magic the fuzzer now contains charsets:-

http://www.businessinfo.co.uk/labs/javascript_protocol_fuzzer/javascript_protocol_fuzzer.php?charset=UTF-8</description>
		<content:encoded><![CDATA[<p>And as if by magic the fuzzer now contains charsets:-</p>
<p><a href="http://www.businessinfo.co.uk/labs/javascript_protocol_fuzzer/javascript_protocol_fuzzer.php?charset=UTF-8" rel="nofollow">http://www.businessinfo.co.uk/labs/javascript_protocol_fuzzer/javascript_protocol_fuzzer.php?charset=UTF-8</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/#comment-1313</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 18 Sep 2008 07:26:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=215#comment-1313</guid>
		<description>@Chris

That's a good point I've not even tried fuzzing with different charsets, at the moment it isn't specified. I may include this option.

Yeah seen your post about that, it's similar to the direction reversal chars mario found when implementing phpids.

I've not tried the latest version of Opera they could have been fixed because it's been quite a while.</description>
		<content:encoded><![CDATA[<p>@Chris</p>
<p>That&#8217;s a good point I&#8217;ve not even tried fuzzing with different charsets, at the moment it isn&#8217;t specified. I may include this option.</p>
<p>Yeah seen your post about that, it&#8217;s similar to the direction reversal chars mario found when implementing phpids.</p>
<p>I&#8217;ve not tried the latest version of Opera they could have been fixed because it&#8217;s been quite a while.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Weber</title>
		<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/#comment-1312</link>
		<dc:creator>Chris Weber</dc:creator>
		<pubDate>Thu, 18 Sep 2008 00:01:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=215#comment-1312</guid>
		<description>Very interesting Gareth - the stuff in Firefox is the entire UTF-16 surrogate range U+DC00 to U+DFFF.  Surrogates have no meaning in UTF-8 so this is weird - were you using a meta tag  or HTTP header to set charset=utf-8 in your testing?


The Opera stuff makes no sense at all to me :) Haha, wow, these code points don't have anything in common in terms of Unicode general categories or binary properties.

Did you see my post about whitespace in Opera?

http://lookout.net/2008/08/26/advisory-attack-of-the-mongolian-space-evaders-and-other-medieval-xss-vectors/

I haven't tried out your Opera links but plan to see if I can figure out what's going on there.</description>
		<content:encoded><![CDATA[<p>Very interesting Gareth - the stuff in Firefox is the entire UTF-16 surrogate range U+DC00 to U+DFFF.  Surrogates have no meaning in UTF-8 so this is weird - were you using a meta tag  or HTTP header to set charset=utf-8 in your testing?</p>
<p>The Opera stuff makes no sense at all to me <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> Haha, wow, these code points don&#8217;t have anything in common in terms of Unicode general categories or binary properties.</p>
<p>Did you see my post about whitespace in Opera?</p>
<p><a href="http://lookout.net/2008/08/26/advisory-attack-of-the-mongolian-space-evaders-and-other-medieval-xss-vectors/" rel="nofollow">http://lookout.net/2008/08/26/advisory-attack-of-the-mongolian-space-evaders-and-other-medieval-xss-vectors/</a></p>
<p>I haven&#8217;t tried out your Opera links but plan to see if I can figure out what&#8217;s going on there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/#comment-1298</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Sun, 07 Sep 2008 18:16:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=215#comment-1298</guid>
		<description>Hey Chris awesome blog! I've bookmarked it :) I'm from the UK so getting to Redmond before Bluehat would be difficult however I might have time just before or after.</description>
		<content:encoded><![CDATA[<p>Hey Chris awesome blog! I&#8217;ve bookmarked it <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> I&#8217;m from the UK so getting to Redmond before Bluehat would be difficult however I might have time just before or after.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Weber</title>
		<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/#comment-1297</link>
		<dc:creator>Chris Weber</dc:creator>
		<pubDate>Sun, 07 Sep 2008 03:54:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=215#comment-1297</guid>
		<description>Gareth, I think we've been doing some similar testing in this area, might be nice to chat sometime.  I've got some other interesting results in all the browsers as well.  Are you planning to be in Redmond sometime before Bluehat?</description>
		<content:encoded><![CDATA[<p>Gareth, I think we&#8217;ve been doing some similar testing in this area, might be nice to chat sometime.  I&#8217;ve got some other interesting results in all the browsers as well.  Are you planning to be in Redmond sometime before Bluehat?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/#comment-1259</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 02 Jul 2008 08:40:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=215#comment-1259</guid>
		<description>@Mikael

I see your point, you now should be able to download the file with wget without spoofing.</description>
		<content:encoded><![CDATA[<p>@Mikael</p>
<p>I see your point, you now should be able to download the file with wget without spoofing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mikael Gueck</title>
		<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/#comment-1258</link>
		<dc:creator>Mikael Gueck</dc:creator>
		<pubDate>Wed, 02 Jul 2008 03:29:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=215#comment-1258</guid>
		<description>Certainly, but you have to spoof the referer as well.</description>
		<content:encoded><![CDATA[<p>Certainly, but you have to spoof the referer as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/06/30/javascript-protocol-fuzz-results/#comment-1257</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 01 Jul 2008 09:07:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=215#comment-1257</guid>
		<description>Easy spoof the user agent e.g.

curl -A 'Internet Explorer' http://www.businessinfo.co.uk/labs/javascript_protocol_fuzzer/vectors.xml</description>
		<content:encoded><![CDATA[<p>Easy spoof the user agent e.g.</p>
<p>curl -A &#8216;Internet Explorer&#8217; <a href="http://www.businessinfo.co.uk/labs/javascript_protocol_fuzzer/vectors.xml" rel="nofollow">http://www.businessinfo.co.uk/labs/javascript_protocol_fuzzer/vectors.xml</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
