<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: HScan Redux</title>
	<atom:link href="http://www.gnucitizen.org/blog/hscan-redux/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/hscan-redux/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Mon, 12 Dec 2011 19:56:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
	<item>
		<title>By: 83 teknik haking baru&#8230; &#171; [dot]EXE - Teknik Elektro Unnes</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-122518</link>
		<dc:creator>83 teknik haking baru&#8230; &#171; [dot]EXE - Teknik Elektro Unnes</dc:creator>
		<pubDate>Fri, 13 Jun 2008 06:28:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-122518</guid>
		<description>[...] HScan Redux [...]</description>
		<content:encoded><![CDATA[<p>[...] HScan Redux [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mozzio</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-11095</link>
		<dc:creator>mozzio</dc:creator>
		<pubDate>Thu, 29 Mar 2007 17:12:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-11095</guid>
		<description>No surprise, any version of the Mozilla browsers with NoScript installed is immune.

http://noscript.net</description>
		<content:encoded><![CDATA[<p>No surprise, any version of the Mozilla browsers with NoScript installed is immune.</p>
<p><a href="http://noscript.net" rel="nofollow">http://noscript.net</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; Noscript HScan</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5599</link>
		<dc:creator>GNUCITIZEN &#187; Noscript HScan</dc:creator>
		<pubDate>Wed, 28 Feb 2007 23:01:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5599</guid>
		<description>[...] Noscript HScan published: February 28th, 2007 After releasing my Firefox specific history scanner, RSnake came up with his own bleeding edge history scanning technique which is based on Jeremiah Grossman&#8217;s implementation but it does not require JavaScript. This approach has its own limitations and advantages. [...]</description>
		<content:encoded><![CDATA[<p>[...] Noscript HScan published: February 28th, 2007 After releasing my Firefox specific history scanner, RSnake came up with his own bleeding edge history scanning technique which is based on Jeremiah Grossman&#8217;s implementation but it does not require JavaScript. This approach has its own limitations and advantages. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ha.ckers.org web application security lab - Archive &#187; Steal Browser History Without JavaScript</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5573</link>
		<dc:creator>ha.ckers.org web application security lab - Archive &#187; Steal Browser History Without JavaScript</dc:creator>
		<pubDate>Wed, 28 Feb 2007 17:24:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5573</guid>
		<description>[...] Before that Jeremiah also came up with the original CSS history hack as you may or may not remember. Later on pdp came up with another variant of the same issue using a very different technique (Firefox caching). Both of those techniques were cool, but both of them also required that you have JavaScript turned on. We all know there are still people out there who think turning off JavaScript protects them from everything. [...]</description>
		<content:encoded><![CDATA[<p>[...] Before that Jeremiah also came up with the original CSS history hack as you may or may not remember. Later on pdp came up with another variant of the same issue using a very different technique (Firefox caching). Both of those techniques were cool, but both of them also required that you have JavaScript turned on. We all know there are still people out there who think turning off JavaScript protects them from everything. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5470</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Tue, 27 Feb 2007 19:32:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5470</guid>
		<description>Don&#039;t work in my Mozilla 1.7.7 :P (and in old version of Firefox).

Old version browsers rulez! :-) Want to save your history - use old school browsers.</description>
		<content:encoded><![CDATA[<p>Don&#8217;t work in my Mozilla 1.7.7 :P (and in old version of Firefox).</p>
<p>Old version browsers rulez! :-) Want to save your history &#8211; use old school browsers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ha.ckers.org web application security lab - Archive &#187; Firefox History Stealing Part 2</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5335</link>
		<dc:creator>ha.ckers.org web application security lab - Archive &#187; Firefox History Stealing Part 2</dc:creator>
		<pubDate>Mon, 26 Feb 2007 00:34:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5335</guid>
		<description>[...] pdp has a really interesting demo code that steals Firefox history using the about-cache directive in Firefox. This is a different method than we&#8217;ve seen before, and is quite a bit slower in his demo than Jeremiah&#8217;s version but it&#8217;s equally clever. If you read his post he describes how this is different than the looking at link color, but you get the idea. [...]</description>
		<content:encoded><![CDATA[<p>[...] pdp has a really interesting demo code that steals Firefox history using the about-cache directive in Firefox. This is a different method than we&#8217;ve seen before, and is quite a bit slower in his demo than Jeremiah&#8217;s version but it&#8217;s equally clever. If you read his post he describes how this is different than the looking at link color, but you get the idea. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5312</link>
		<dc:creator>Jordan</dc:creator>
		<pubDate>Sun, 25 Feb 2007 15:53:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5312</guid>
		<description>Doesn&#039;t work for me, OS X, FF 2.0.0.1 but it&#039;s probably SafeCache or SafeHistory blocking it.

http://safecache.com/
http://safehistory.com/</description>
		<content:encoded><![CDATA[<p>Doesn&#8217;t work for me, OS X, FF 2.0.0.1 but it&#8217;s probably SafeCache or SafeHistory blocking it.</p>
<p><a href="http://safecache.com/" rel="nofollow">http://safecache.com/</a><br />
<a href="http://safehistory.com/" rel="nofollow">http://safehistory.com/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adriaan</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5232</link>
		<dc:creator>Adriaan</dc:creator>
		<pubDate>Sat, 24 Feb 2007 10:16:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5232</guid>
		<description>Indeed. Does not work under gentoo linux, 2.0.0.1.</description>
		<content:encoded><![CDATA[<p>Indeed. Does not work under gentoo linux, 2.0.0.1.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dusoft</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5216</link>
		<dc:creator>dusoft</dc:creator>
		<pubDate>Sat, 24 Feb 2007 01:45:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5216</guid>
		<description>Does not work for Firefox 2.0.0.1 under Linux</description>
		<content:encoded><![CDATA[<p>Does not work for Firefox 2.0.0.1 under Linux</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5205</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 23 Feb 2007 22:26:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5205</guid>
		<description>It works on Mac OS 10.4.8 Firefox 2.0.0.1 too.</description>
		<content:encoded><![CDATA[<p>It works on Mac OS 10.4.8 Firefox 2.0.0.1 too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: -am</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5198</link>
		<dc:creator>-am</dc:creator>
		<pubDate>Fri, 23 Feb 2007 20:51:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5198</guid>
		<description>Works on FF 1.5.0.9/WinXP. Good catch :)</description>
		<content:encoded><![CDATA[<p>Works on FF 1.5.0.9/WinXP. Good catch :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5193</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Fri, 23 Feb 2007 15:45:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5193</guid>
		<description>Thanx ;) I did a little quick test and from what i acn say it is hard to impossible. I will give it a deeper look tomorrow.

I used it on a jquery featured site trying this:

&lt;pre&gt;&lt;code&gt;$.get(&#039;about:cache?device=disk&#039;, function(response){alert(response);});&lt;/code&gt;&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>Thanx ;) I did a little quick test and from what i acn say it is hard to impossible. I will give it a deeper look tomorrow.</p>
<p>I used it on a jquery featured site trying this:</p>
<pre><code>$.get('about:cache?device=disk', function(response){alert(response);});</code></pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5192</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 23 Feb 2007 15:40:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5192</guid>
		<description>sorry man, fixed it. I am almost certain that you cannot read about:cache with XMLHttpRequest.</description>
		<content:encoded><![CDATA[<p>sorry man, fixed it. I am almost certain that you cannot read about:cache with XMLHttpRequest.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5191</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Fri, 23 Feb 2007 15:37:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5191</guid>
		<description>What about XHRing the URL about:cache?device=disk and parsing out all URLs from the response body via regex? Then you&#039;d have a complete history theft - guess i have to test that tomorrow.

BTW, it&#039;s .mario with an o...</description>
		<content:encoded><![CDATA[<p>What about XHRing the URL about:cache?device=disk and parsing out all URLs from the response body via regex? Then you&#8217;d have a complete history theft &#8211; guess i have to test that tomorrow.</p>
<p>BTW, it&#8217;s .mario with an o&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: duk</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5186</link>
		<dc:creator>duk</dc:creator>
		<pubDate>Fri, 23 Feb 2007 14:46:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5186</guid>
		<description>Firefox 2.0.0.2 is also vulnerable</description>
		<content:encoded><![CDATA[<p>Firefox 2.0.0.2 is also vulnerable</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5184</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 23 Feb 2007 14:06:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5184</guid>
		<description>.mario about:cache is actually a protocol to access Firefox internal cache information. There are a few other about: directives. about:mozilla is fun.</description>
		<content:encoded><![CDATA[<p>.mario about:cache is actually a protocol to access Firefox internal cache information. There are a few other about: directives. about:mozilla is fun.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://www.gnucitizen.org/blog/hscan-redux/comment-page-1/#comment-5183</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Fri, 23 Feb 2007 14:04:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/hscan-redux#comment-5183</guid>
		<description>This is a very interesting approach of history stealing! I didn&#039;t know about the about:cache-entry directive. I guess i will spend some time the next days to check what other about: directives are available and maybe exploitable...

Great find!</description>
		<content:encoded><![CDATA[<p>This is a very interesting approach of history stealing! I didn&#8217;t know about the about:cache-entry directive. I guess i will spend some time the next days to check what other about: directives are available and maybe exploitable&#8230;</p>
<p>Great find!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

