<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Cross Context Scripting with Sage</title>
	<atom:link href="http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Fri, 21 Nov 2008 21:31:50 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: GNUCITIZEN &#187; Firebug Goes Evil</title>
		<link>http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/#comment-12721</link>
		<dc:creator>GNUCITIZEN &#187; Firebug Goes Evil</dc:creator>
		<pubDate>Wed, 04 Apr 2007 19:12:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-context-scripting-with-sage#comment-12721</guid>
		<description>[...] Unfortunately, Firebug suffers from rather simple but quite dangerous vulnerability. I have discussed the issues that browsers like Firefox, Opera, IE and Safary face these days on this web site. In general, these browsers try their best to prevent common vulnerabilities from crippling into their source code. However, that&#8217;s not the case with browser extensions. Very often, browser extension authors do not consider the security aspects of their work that much. Because of this, vulnerabilities occur. Believe me or not, the next wave of browser attacks will target exactly that. [...]</description>
		<content:encoded><![CDATA[<p>[...] Unfortunately, Firebug suffers from rather simple but quite dangerous vulnerability. I have discussed the issues that browsers like Firefox, Opera, IE and Safary face these days on this web site. In general, these browsers try their best to prevent common vulnerabilities from crippling into their source code. However, that&#8217;s not the case with browser extensions. Very often, browser extension authors do not consider the security aspects of their work that much. Because of this, vulnerabilities occur. Believe me or not, the next wave of browser attacks will target exactly that. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Andrews</title>
		<link>http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/#comment-175</link>
		<dc:creator>Peter Andrews</dc:creator>
		<pubDate>Tue, 03 Oct 2006 06:13:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-context-scripting-with-sage#comment-175</guid>
		<description>This issue has now been addressed with the release of Sage 1.3.7

http://mozdev.org/bugs/show_bug.cgi?id=15101

Thanks for your concern.</description>
		<content:encoded><![CDATA[<p>This issue has now been addressed with the release of Sage 1.3.7</p>
<p><a href="http://mozdev.org/bugs/show_bug.cgi?id=15101" rel="nofollow">http://mozdev.org/bugs/show_bug.cgi?id=15101</a></p>
<p>Thanks for your concern.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A Thornton</title>
		<link>http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/#comment-72</link>
		<dc:creator>A Thornton</dc:creator>
		<pubDate>Fri, 15 Sep 2006 10:05:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-context-scripting-with-sage#comment-72</guid>
		<description>Look at how long this bug has been open - probably not a good sign:

http://mozdev.org/bugs/show_bug.cgi?id=13744</description>
		<content:encoded><![CDATA[<p>Look at how long this bug has been open - probably not a good sign:</p>
<p><a href="http://mozdev.org/bugs/show_bug.cgi?id=13744" rel="nofollow">http://mozdev.org/bugs/show_bug.cgi?id=13744</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: firefox extensions &#187; Blog Archive &#187; Cross-site scripting attacks via Sage Firefox Extension.</title>
		<link>http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/#comment-68</link>
		<dc:creator>firefox extensions &#187; Blog Archive &#187; Cross-site scripting attacks via Sage Firefox Extension.</dc:creator>
		<pubDate>Tue, 12 Sep 2006 21:06:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-context-scripting-with-sage#comment-68</guid>
		<description>[...] Theres a proof of concept feed demo at this URL. [...]</description>
		<content:encoded><![CDATA[<p>[...] Theres a proof of concept feed demo at this URL. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/#comment-65</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 11 Sep 2006 15:15:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-context-scripting-with-sage#comment-65</guid>
		<description>Thanks Robert, the slides are quite good</description>
		<content:encoded><![CDATA[<p>Thanks Robert, the slides are quite good</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: robert</title>
		<link>http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/#comment-64</link>
		<dc:creator>robert</dc:creator>
		<pubDate>Mon, 11 Sep 2006 12:57:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-context-scripting-with-sage#comment-64</guid>
		<description>Hello I am the author of the whitepaper, and blackhat presentation of which you speak. The slides to my talk can be found below.

RSS Slideshow
http://www.cgisecurity.com/papers/RSS-Security.ppt

RSS Security Repository
http://www.cgisecurity.com/rss/</description>
		<content:encoded><![CDATA[<p>Hello I am the author of the whitepaper, and blackhat presentation of which you speak. The slides to my talk can be found below.</p>
<p>RSS Slideshow<br />
<a href="http://www.cgisecurity.com/papers/RSS-Security.ppt" rel="nofollow">http://www.cgisecurity.com/papers/RSS-Security.ppt</a></p>
<p>RSS Security Repository<br />
<a href="http://www.cgisecurity.com/rss/" rel="nofollow">http://www.cgisecurity.com/rss/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/#comment-57</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sat, 09 Sep 2006 06:13:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-context-scripting-with-sage#comment-57</guid>
		<description>Although the original feed works in my browser, using the send method the way you are suggesting is more accurate so I fixed the feed. Thanks for that.</description>
		<content:encoded><![CDATA[<p>Although the original feed works in my browser, using the send method the way you are suggesting is more accurate so I fixed the feed. Thanks for that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Operation n &#187; Blog Archive &#187; Cross Context Scripting with Sage</title>
		<link>http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/#comment-56</link>
		<dc:creator>Operation n &#187; Blog Archive &#187; Cross Context Scripting with Sage</dc:creator>
		<pubDate>Sat, 09 Sep 2006 05:52:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-context-scripting-with-sage#comment-56</guid>
		<description>[...] See GNUCITIZEN more proof of concept example. [...]</description>
		<content:encoded><![CDATA[<p>[...] See GNUCITIZEN more proof of concept example. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jürgen R. Plasser</title>
		<link>http://www.gnucitizen.org/blog/cross-context-scripting-with-sage/#comment-55</link>
		<dc:creator>Jürgen R. Plasser</dc:creator>
		<pubDate>Fri, 08 Sep 2006 21:23:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-context-scripting-with-sage#comment-55</guid>
		<description>The feed did not work for me, so I looked closer and saw that request.send() throughs exceptions (which try catches). I simply added null as parameter to send: request.send(null). Then it worked.</description>
		<content:encoded><![CDATA[<p>The feed did not work for me, so I looked closer and saw that request.send() throughs exceptions (which try catches). I simply added null as parameter to send: request.send(null). Then it worked.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
