<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Severe XSS in Google and Others due to the JAR protocol issues</title>
	<atom:link href="http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/</link>
	<description>Cutting-edge Think tank &#124; Ethical Hacker Outfit</description>
	<pubDate>Fri, 04 Jul 2008 17:16:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Komputery - Blog z nowościami ze świata komputerów &#187; Luka w Firefoksie obejmuje użytkowników Gmail</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-75401</link>
		<dc:creator>Komputery - Blog z nowościami ze świata komputerów &#187; Luka w Firefoksie obejmuje użytkowników Gmail</dc:creator>
		<pubDate>Thu, 22 Nov 2007 07:41:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-75401</guid>
		<description>[...] w coraz większej ilości stron Internetowych, w tym giganta &#8212; wyszukiwarki Google. Portal GnuCitizen napisał, że sprawą zainteresował się Michał Zalewski, aktualnie pracujący w Googleplex, [...]</description>
		<content:encoded><![CDATA[<p>[...] w coraz większej ilości stron Internetowych, w tym giganta &#8212; wyszukiwarki Google. Portal GnuCitizen napisał, że sprawą zainteresował się Michał Zalewski, aktualnie pracujący w Googleplex, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luka w Firefoksie obejmuje uÅ¼ytkownikÃ³w Gmail &#124; Komputery, internet serwis</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-75077</link>
		<dc:creator>Luka w Firefoksie obejmuje uÅ¼ytkownikÃ³w Gmail &#124; Komputery, internet serwis</dc:creator>
		<pubDate>Wed, 21 Nov 2007 13:53:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-75077</guid>
		<description>[...] wiÄ™kszej iloÅ›ci stron Internetowych, w tym giganta &#8212; wyszukiwarki Google. Portal GnuCitizen napisaÅ‚, Å¼e sprawÄ… zainteresowaÅ‚ siÄ™ MichaÅ‚ Zalewski, aktualnie [...]</description>
		<content:encoded><![CDATA[<p>[...] wiÄ™kszej iloÅ›ci stron Internetowych, w tym giganta &#8212; wyszukiwarki Google. Portal GnuCitizen napisaÅ‚, Å¼e sprawÄ… zainteresowaÅ‚ siÄ™ MichaÅ‚ Zalewski, aktualnie [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cyphersec.com &#187; Redirectors, cosa sono e come funzionano</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-74507</link>
		<dc:creator>cyphersec.com &#187; Redirectors, cosa sono e come funzionano</dc:creator>
		<pubDate>Tue, 20 Nov 2007 15:17:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-74507</guid>
		<description>[...] [link] direttamente da gnucitizen.org pdp comunica una vulnerabilità sul protocollo jar la quale si basa [...]</description>
		<content:encoded><![CDATA[<p>[...] [link] direttamente da gnucitizen.org pdp comunica una vulnerabilità sul protocollo jar la quale si basa [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Najnowsze Wiadomości Internetowe &#187; Luka w Firefoksie obejmuje użytkowników Gmail</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-74487</link>
		<dc:creator>Najnowsze Wiadomości Internetowe &#187; Luka w Firefoksie obejmuje użytkowników Gmail</dc:creator>
		<pubDate>Tue, 20 Nov 2007 14:38:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-74487</guid>
		<description>[...] w coraz większej ilości stron Internetowych, w tym giganta &#8212; wyszukiwarki Google. Portal GnuCitizen napisał, że sprawą zainteresował się Michał Zalewski, aktualnie pracujący w Googleplex, [...]</description>
		<content:encoded><![CDATA[<p>[...] w coraz większej ilości stron Internetowych, w tym giganta &#8212; wyszukiwarki Google. Portal GnuCitizen napisał, że sprawą zainteresował się Michał Zalewski, aktualnie pracujący w Googleplex, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nicolas</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-71737</link>
		<dc:creator>Nicolas</dc:creator>
		<pubDate>Fri, 16 Nov 2007 03:06:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-71737</guid>
		<description>vaj your sarcasm generator is very broken. Sarcasm just doesn't work on Internet.</description>
		<content:encoded><![CDATA[<p>vaj your sarcasm generator is very broken. Sarcasm just doesn&#8217;t work on Internet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ronald</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-71632</link>
		<dc:creator>ronald</dc:creator>
		<pubDate>Thu, 15 Nov 2007 23:18:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-71632</guid>
		<description>@vaj

shellcode isn't complex, it only takes huge amounts of time to construct a correct payload, and that payload could chnage due to some conditions, and might not work all the time.
So no mumbo jumbo about "hacking" and "shellcode" because it looks difficult, while it really isn't. The principles behind it are easy to grasp.

I understand what message you try to send here, but you can't say hacking is "this" or "that". Mainly for the fact that most buffer overflows all work the same, the creation of shellcode is only a process, just like programming is. If you like spending countless hours attaching crashing programs to a debugger, in order to construct decent shellcode, well that's your kick then.

I do agree however that the "jar" issue isn't bad. I don't think it's such a big issue, but that is my opinion. For the reason that a) I knew about it. b) Firefox/extensions boot up out jars. c) It's actually used for a signed javascript archives for years. d) never trust content.</description>
		<content:encoded><![CDATA[<p>@vaj</p>
<p>shellcode isn&#8217;t complex, it only takes huge amounts of time to construct a correct payload, and that payload could chnage due to some conditions, and might not work all the time.<br />
So no mumbo jumbo about &#8220;hacking&#8221; and &#8220;shellcode&#8221; because it looks difficult, while it really isn&#8217;t. The principles behind it are easy to grasp.</p>
<p>I understand what message you try to send here, but you can&#8217;t say hacking is &#8220;this&#8221; or &#8220;that&#8221;. Mainly for the fact that most buffer overflows all work the same, the creation of shellcode is only a process, just like programming is. If you like spending countless hours attaching crashing programs to a debugger, in order to construct decent shellcode, well that&#8217;s your kick then.</p>
<p>I do agree however that the &#8220;jar&#8221; issue isn&#8217;t bad. I don&#8217;t think it&#8217;s such a big issue, but that is my opinion. For the reason that a) I knew about it. b) Firefox/extensions boot up out jars. c) It&#8217;s actually used for a signed javascript archives for years. d) never trust content.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: XAM &#187; Blog Archive &#187; Luka w Firefoksie obejmuje użytkowników Gmail</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-70936</link>
		<dc:creator>XAM &#187; Blog Archive &#187; Luka w Firefoksie obejmuje użytkowników Gmail</dc:creator>
		<pubDate>Thu, 15 Nov 2007 01:49:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-70936</guid>
		<description>[...] w coraz większej ilości stron Internetowych, w tym giganta &#8212; wyszukiwarki Google. Portal GnuCitizen napisał, że sprawą zainteresował się Michał Zalewski, aktualnie pracujący w Googleplex, [...]</description>
		<content:encoded><![CDATA[<p>[...] w coraz większej ilości stron Internetowych, w tym giganta &mdash; wyszukiwarki Google. Portal GnuCitizen napisał, że sprawą zainteresował się Michał Zalewski, aktualnie pracujący w Googleplex, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vaj</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-70927</link>
		<dc:creator>vaj</dc:creator>
		<pubDate>Thu, 15 Nov 2007 01:29:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-70927</guid>
		<description>pdp your sarcasm detector is very broken :)</description>
		<content:encoded><![CDATA[<p>pdp your sarcasm detector is very broken :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nicolas</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-70888</link>
		<dc:creator>Nicolas</dc:creator>
		<pubDate>Thu, 15 Nov 2007 00:19:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-70888</guid>
		<description>Oh yeah, hacking a dhcpd is the only thing that is actually hacking. LOL what an idiot XD</description>
		<content:encoded><![CDATA[<p>Oh yeah, hacking a dhcpd is the only thing that is actually hacking. LOL what an idiot XD</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zapphod</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-70823</link>
		<dc:creator>Zapphod</dc:creator>
		<pubDate>Wed, 14 Nov 2007 21:52:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-70823</guid>
		<description>vaj -  Hillarious!  They don't get ya!</description>
		<content:encoded><![CDATA[<p>vaj -  Hillarious!  They don&#8217;t get ya!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luka w Firefoksie obejmuje użytkowników Gmail &#124; thecamels.org</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-70816</link>
		<dc:creator>Luka w Firefoksie obejmuje użytkowników Gmail &#124; thecamels.org</dc:creator>
		<pubDate>Wed, 14 Nov 2007 21:45:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-70816</guid>
		<description>[...] ilości stron internetowych. Tym razem ofiarami ataku stali się użytkownicy poczty Gmail.  Portal GnuCitizen napisał, że sprawą zainteresował Michał Zalewski. Obecnie pracuje on dla Googleplex. Na [...]</description>
		<content:encoded><![CDATA[<p>[...] ilości stron internetowych. Tym razem ofiarami ataku stali się użytkownicy poczty Gmail.  Portal GnuCitizen napisał, że sprawą zainteresował Michał Zalewski. Obecnie pracuje on dla Googleplex. Na [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luka w Firefoksie obejmuje użytkowników Gmail - IT Blog</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-70516</link>
		<dc:creator>Luka w Firefoksie obejmuje użytkowników Gmail - IT Blog</dc:creator>
		<pubDate>Wed, 14 Nov 2007 10:16:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-70516</guid>
		<description>[...] jej w coraz większej ilości stron Internetowych, w tym giganta wyszukiwarki Google. Portal GnuCitizen napisał, że sprawą zainteresował Michał Zalewski, aktualnie pracujący dla Googleplex, [...]</description>
		<content:encoded><![CDATA[<p>[...] jej w coraz większej ilości stron Internetowych, w tym giganta wyszukiwarki Google. Portal GnuCitizen napisał, że sprawą zainteresował Michał Zalewski, aktualnie pracujący dla Googleplex, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-70428</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 14 Nov 2007 06:29:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-70428</guid>
		<description>&lt;blockquote&gt;xss is not hacking because it needs interact from target&lt;/blockquote&gt;

so does every other client-side exploit, even if it is BF or whatever else. what do u define as hacking?

&lt;blockquote&gt;only buffer overflow of openbsd dhcpd is hacking, because every important target use openbsd for everything. that is why openbsd dhcpd exploit is the greatest hacking of all time.&lt;/blockquote&gt;

you are either script kiddie or you have no idea about the security business and industry at all.

&lt;blockquote&gt;because shellcode is complex&lt;/blockquote&gt;

haha :) shellcode is complex? right! I guess it is complex to you because you cannot write it.

&lt;blockquote&gt;user interaction is lame except if u distribute backdoor exploit code for openbsd dhcpd exploit and user compile and run backdoor and then you own whitehat security company and then u write a zine about it.&lt;/blockquote&gt;

why do u keep mentioning BSD? what is with that? My friendly advise to you is to open your mind a little bit and stop being a sheep. Security is such a vast topic. Restricting yourself one single thing wont bring you anything good and will make you sound retarded. So, keep up with your instincts but do not judge things that you simple don't understand.</description>
		<content:encoded><![CDATA[<blockquote><p>xss is not hacking because it needs interact from target</p></blockquote>
<p>so does every other client-side exploit, even if it is BF or whatever else. what do u define as hacking?</p>
<blockquote><p>only buffer overflow of openbsd dhcpd is hacking, because every important target use openbsd for everything. that is why openbsd dhcpd exploit is the greatest hacking of all time.</p></blockquote>
<p>you are either script kiddie or you have no idea about the security business and industry at all.</p>
<blockquote><p>because shellcode is complex</p></blockquote>
<p>haha :) shellcode is complex? right! I guess it is complex to you because you cannot write it.</p>
<blockquote><p>user interaction is lame except if u distribute backdoor exploit code for openbsd dhcpd exploit and user compile and run backdoor and then you own whitehat security company and then u write a zine about it.</p></blockquote>
<p>why do u keep mentioning BSD? what is with that? My friendly advise to you is to open your mind a little bit and stop being a sheep. Security is such a vast topic. Restricting yourself one single thing wont bring you anything good and will make you sound retarded. So, keep up with your instincts but do not judge things that you simple don&#8217;t understand.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vaj</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-70302</link>
		<dc:creator>vaj</dc:creator>
		<pubDate>Wed, 14 Nov 2007 00:17:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-70302</guid>
		<description>xss is not hacking because it needs interact from target

only buffer overflow of openbsd dhcpd is hacking, because every important target use openbsd for everything. that is why openbsd dhcpd exploit is the greatest hacking of all time.

no hacker is interested in hacking workstation of employee of target company and bouncing from internal workstation to sensitive data. this is not hacking because the workstation do not use openbsd dhcpd and hacker did not have to write shellcode.

because shellcode is complex, xss is not complex, therefore u should never use it to hack because only reason to hack is to impress other hackers with your exploit, not to get data or compromise network

user interaction is lame except if u distribute backdoor exploit code for openbsd dhcpd exploit and user compile and run backdoor and then you own  whitehat security company and then u write a zine about it.</description>
		<content:encoded><![CDATA[<p>xss is not hacking because it needs interact from target</p>
<p>only buffer overflow of openbsd dhcpd is hacking, because every important target use openbsd for everything. that is why openbsd dhcpd exploit is the greatest hacking of all time.</p>
<p>no hacker is interested in hacking workstation of employee of target company and bouncing from internal workstation to sensitive data. this is not hacking because the workstation do not use openbsd dhcpd and hacker did not have to write shellcode.</p>
<p>because shellcode is complex, xss is not complex, therefore u should never use it to hack because only reason to hack is to impress other hackers with your exploit, not to get data or compromise network</p>
<p>user interaction is lame except if u distribute backdoor exploit code for openbsd dhcpd exploit and user compile and run backdoor and then you own  whitehat security company and then u write a zine about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-70147</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 13 Nov 2007 15:30:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-70147</guid>
		<description>vaj, you are sarcastic right?</description>
		<content:encoded><![CDATA[<p>vaj, you are sarcastic right?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vaj</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-69866</link>
		<dc:creator>vaj</dc:creator>
		<pubDate>Mon, 12 Nov 2007 22:55:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-69866</guid>
		<description>this is the lame this is not hacking
BUFFEROVERFLOW IS HACKING
(c;</description>
		<content:encoded><![CDATA[<p>this is the lame this is not hacking<br />
BUFFEROVERFLOW IS HACKING<br />
(c;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SecuriTeam Blogs &#187; JAR: protocol vuln - targeting to Google now</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-69545</link>
		<dc:creator>SecuriTeam Blogs &#187; JAR: protocol vuln - targeting to Google now</dc:creator>
		<pubDate>Mon, 12 Nov 2007 05:47:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-69545</guid>
		<description>[...] Severe XSS in Google and Others due to JAR protocol issues [...]</description>
		<content:encoded><![CDATA[<p>[...] Severe XSS in Google and Others due to JAR protocol issues [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-68846</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sat, 10 Nov 2007 22:36:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-68846</guid>
		<description>you never know ;)</description>
		<content:encoded><![CDATA[<p>you never know ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-68812</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Sat, 10 Nov 2007 21:46:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-68812</guid>
		<description>"no one is safe"... a bit unfair to me ;)</description>
		<content:encoded><![CDATA[<p>&#8220;no one is safe&#8221;&#8230; a bit unfair to me ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vindic</title>
		<link>http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues/#comment-68735</link>
		<dc:creator>vindic</dc:creator>
		<pubDate>Sat, 10 Nov 2007 19:30:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issues#comment-68735</guid>
		<description>pdp this is amazing post, thank you for you gr8 work ;)</description>
		<content:encoded><![CDATA[<p>pdp this is amazing post, thank you for you gr8 work ;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
