<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Web Mayhem: Firefox&#8217;s JAR: Protocol issues</title>
	<atom:link href="http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Firefox 2.0 : 9 mois pour accoucher d&#8217;un correctif de sÃ©curitÃ© â€” SecurityVibes Magazine</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-129776</link>
		<dc:creator>Firefox 2.0 : 9 mois pour accoucher d&#8217;un correctif de sÃ©curitÃ© â€” SecurityVibes Magazine</dc:creator>
		<pubDate>Wed, 23 Mar 2011 15:16:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-129776</guid>
		<description>[...] dÃ©but de mois, le dÃ©sormais cÃ©lÃ¨bre Petko D. Petkov faisait une nouvelle fois parler de lui en alertant [...]</description>
		<content:encoded><![CDATA[<p>[...] dÃ©but de mois, le dÃ©sormais cÃ©lÃ¨bre Petko D. Petkov faisait une nouvelle fois parler de lui en alertant [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: corrector</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-127883</link>
		<dc:creator>corrector</dc:creator>
		<pubDate>Thu, 01 Oct 2009 20:35:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-127883</guid>
		<description>&quot;Never heard of that â€œjar:â€ protocol. I wonder if this issue has been fixed by Google, Microsoft and everyone else since this post.&quot; Hug? What is this nonsense all about? There is not/was not, &quot;a Google, MS and every one else&quot; bug. There is (was) an awful, ridiculous, crazy, MS-sh*tware-style exploit-invitation-by-design FF obscenity. No one needs to fix anything except Mozilla. Someone needs to be fired, and that someone is actually so many people. FF credibility is ruined *forever* (or until this team is fired for good).</description>
		<content:encoded><![CDATA[<p>&#8220;Never heard of that â€œjar:â€ protocol. I wonder if this issue has been fixed by Google, Microsoft and everyone else since this post.&#8221; Hug? What is this nonsense all about? There is not/was not, &#8220;a Google, MS and every one else&#8221; bug. There is (was) an awful, ridiculous, crazy, MS-sh*tware-style exploit-invitation-by-design FF obscenity. No one needs to fix anything except Mozilla. Someone needs to be fired, and that someone is actually so many people. FF credibility is ruined *forever* (or until this team is fired for good).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anti-Virus &#38; Anti-Malware website. &#187; Firefox 2 Security Update Coming</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-127661</link>
		<dc:creator>Anti-Virus &#38; Anti-Malware website. &#187; Firefox 2 Security Update Coming</dc:creator>
		<pubDate>Fri, 31 Jul 2009 12:16:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-127661</guid>
		<description>[...] cross-site scripting,&#8221; said Petko Petkov, founder of security consultancy gnucitizen.org, in blog post earlier this month. &#8220;Potential targets for this attack include applications such as Web mail [...]</description>
		<content:encoded><![CDATA[<p>[...] cross-site scripting,&#8221; said Petko Petkov, founder of security consultancy gnucitizen.org, in blog post earlier this month. &#8220;Potential targets for this attack include applications such as Web mail [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nathanr&#124;ca &#187; Firefox Security Threat - Google is vulnerable</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-122458</link>
		<dc:creator>nathanr&#124;ca &#187; Firefox Security Threat - Google is vulnerable</dc:creator>
		<pubDate>Fri, 06 Jun 2008 03:31:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-122458</guid>
		<description>[...] security exploits being discovered and being exploited. The latest threat involves the usage of a malicious JAR file. The flaw is still in the wild and the problem persists with the websites of Major Internet [...]</description>
		<content:encoded><![CDATA[<p>[...] security exploits being discovered and being exploited. The latest threat involves the usage of a malicious JAR file. The flaw is still in the wild and the problem persists with the websites of Major Internet [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: View contents of Zip/Jar files using firefox : Burad&#8217;s Blog</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-121914</link>
		<dc:creator>View contents of Zip/Jar files using firefox : Burad&#8217;s Blog</dc:creator>
		<pubDate>Thu, 15 May 2008 21:49:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-121914</guid>
		<description>[...] that come with jar: protocol While serching for pages related to jar protocol in firefox, I found an interesting article at www.gnucitizen.org In simple terms, it means that any application which allows upload of JAR/ZIP [...]</description>
		<content:encoded><![CDATA[<p>[...] that come with jar: protocol While serching for pages related to jar protocol in firefox, I found an interesting article at <a href="http://www.gnucitizen.org" rel="nofollow">http://www.gnucitizen.org</a> In simple terms, it means that any application which allows upload of JAR/ZIP [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Technology latest news &#187; Blog Archive &#187; Firefox plans bug fix release for next week (InfoWorld)</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-115770</link>
		<dc:creator>Technology latest news &#187; Blog Archive &#187; Firefox plans bug fix release for next week (InfoWorld)</dc:creator>
		<pubDate>Sun, 02 Mar 2008 22:58:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-115770</guid>
		<description>[...] the browser during a quality assurance &#8220;testday&#8221; this Friday.   The issue was first pointed out on his blog that the flaw could be used to launch a cross-site scripting attack against the Firefox [...]</description>
		<content:encoded><![CDATA[<p>[...] the browser during a quality assurance &#8220;testday&#8221; this Friday.   The issue was first pointed out on his blog that the flaw could be used to launch a cross-site scripting attack against the Firefox [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sanjuro</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-115743</link>
		<dc:creator>sanjuro</dc:creator>
		<pubDate>Fri, 29 Feb 2008 13:17:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-115743</guid>
		<description>Never heard of that &quot;jar:&quot; protocol. I wonder if this issue has been fixed by Google, Microsoft and everyone else since this post.</description>
		<content:encoded><![CDATA[<p>Never heard of that &#8220;jar:&#8221; protocol. I wonder if this issue has been fixed by Google, Microsoft and everyone else since this post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J a C k N e w s &#187; Blog Archive &#187; Top Tep Web Hacks of 2007</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-106480</link>
		<dc:creator>J a C k N e w s &#187; Blog Archive &#187; Top Tep Web Hacks of 2007</dc:creator>
		<pubDate>Thu, 31 Jan 2008 15:09:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-106480</guid>
		<description>[...] Firefoxâ€™s JAR: Protocol issues [...]</description>
		<content:encoded><![CDATA[<p>[...] Firefoxâ€™s JAR: Protocol issues [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: neobe&#8217;s Blog - ActualitÃ©s Stockage et SÃ©curitÃ© &#187; Blog Archive &#187; Le top 10 des hacks "web" 2007</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-105097</link>
		<dc:creator>neobe&#8217;s Blog - ActualitÃ©s Stockage et SÃ©curitÃ© &#187; Blog Archive &#187; Le top 10 des hacks "web" 2007</dc:creator>
		<pubDate>Tue, 29 Jan 2008 11:24:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-105097</guid>
		<description>[...] Les problÃ¨mes des fichiers JAR sous Firefox [...]</description>
		<content:encoded><![CDATA[<p>[...] Les problÃ¨mes des fichiers JAR sous Firefox [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firefox ve GÃ¼ncel ZayÄ±flÄ±klarÄ± &#124; SpyArea</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-79929</link>
		<dc:creator>Firefox ve GÃ¼ncel ZayÄ±flÄ±klarÄ± &#124; SpyArea</dc:creator>
		<pubDate>Sat, 01 Dec 2007 20:33:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-79929</guid>
		<description>[...] History DoS Attack  Web Mayhem: Firefox&#8217;s JAR: Protocol issues  Bugs in the Browser: Firefox&#8217;s DATA URL Scheme Vulnerability      &#171; RSnake RÃ¶portajÄ± [...]</description>
		<content:encoded><![CDATA[<p>[...] History DoS Attack  Web Mayhem: Firefox&rsquo;s JAR: Protocol issues  Bugs in the Browser: Firefox&rsquo;s DATA URL Scheme Vulnerability      &laquo; RSnake RÃ¶portajÄ± [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mozilla Corrects Three Vulnerabilities in Firefox 2.0.0.10 &#171; Bardissi Enterprises Blog</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-78400</link>
		<dc:creator>Mozilla Corrects Three Vulnerabilities in Firefox 2.0.0.10 &#171; Bardissi Enterprises Blog</dc:creator>
		<pubDate>Wed, 28 Nov 2007 20:53:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-78400</guid>
		<description>[...] If you&#8217;d like more detail on this complex attack, check out pdp&#8217;s advisories [ 1 / 2 ]. For more general understanding of XSS attacks, see our article, &#8220;Anatomy of a [...]</description>
		<content:encoded><![CDATA[<p>[...] If you&#8217;d like more detail on this complex attack, check out pdp&#8217;s advisories [ 1 / 2 ]. For more general understanding of XSS attacks, see our article, &#8220;Anatomy of a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firefox 2.0.0.10: Neue Version ist erschienen - WinBoard - Die Windows Community</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-77610</link>
		<dc:creator>Firefox 2.0.0.10: Neue Version ist erschienen - WinBoard - Die Windows Community</dc:creator>
		<pubDate>Tue, 27 Nov 2007 11:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-77610</guid>
		<description>[...] November nochmals zusätzliche Aufmerksamkeit bekam, nachdem der Sicherheitsexperte Petko Petkov in einem Blog-Eintrag die Gefährlichkeit der Lücke nachwies.  Zum Schließen einer Speicher-Sicherheitslücke waren [...]</description>
		<content:encoded><![CDATA[<p>[...] November nochmals zusätzliche Aufmerksamkeit bekam, nachdem der Sicherheitsexperte Petko Petkov in einem Blog-Eintrag die Gefährlichkeit der Lücke nachwies.  Zum Schließen einer Speicher-Sicherheitslücke waren [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firefox 2 Security Update Coming</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-76483</link>
		<dc:creator>Firefox 2 Security Update Coming</dc:creator>
		<pubDate>Sat, 24 Nov 2007 19:49:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-76483</guid>
		<description>[...] scripting,&#8221; said Petko Petkov, founder of security consultancy gnucitizen.org, in &#171;www.gnucitizen.org&#187; earlier this month. &#8220;Potential targets for this attack include applications such as [...]</description>
		<content:encoded><![CDATA[<p>[...] scripting,&#8221; said Petko Petkov, founder of security consultancy gnucitizen.org, in &laquo;www.gnucitizen.org&raquo; earlier this month. &#8220;Potential targets for this attack include applications such as [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Business Daily News &#187; Firefox 2 Security Update Coming</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-76481</link>
		<dc:creator>Business Daily News &#187; Firefox 2 Security Update Coming</dc:creator>
		<pubDate>Sat, 24 Nov 2007 19:48:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-76481</guid>
		<description>[...] scripting,&#8221; said Petko Petkov, founder of security consultancy gnucitizen.org, in &#171;www.gnucitizen.org&#187; earlier this month. &#8220;Potential targets for this attack include applications such as [...]</description>
		<content:encoded><![CDATA[<p>[...] scripting,&#8221; said Petko Petkov, founder of security consultancy gnucitizen.org, in &laquo;www.gnucitizen.org&raquo; earlier this month. &#8220;Potential targets for this attack include applications such as [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firefox 2.0.0.10: Neue Version erscheint bereits in Kürze - WinBoard - Die Windows Community</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-75547</link>
		<dc:creator>Firefox 2.0.0.10: Neue Version erscheint bereits in Kürze - WinBoard - Die Windows Community</dc:creator>
		<pubDate>Thu, 22 Nov 2007 14:16:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-75547</guid>
		<description>[...] November nochmals zusätzliche Aufmerksamkeit zukam, nachdem der Sicherheitsexperte Petko Petkov in seinem Blog veröffentlicht hatte, dass diese Lücke auch für Cross-Site-Scripting-Attacken gegen den Firefox-Browser genutzt [...]</description>
		<content:encoded><![CDATA[<p>[...] November nochmals zusätzliche Aufmerksamkeit zukam, nachdem der Sicherheitsexperte Petko Petkov in seinem Blog veröffentlicht hatte, dass diese Lücke auch für Cross-Site-Scripting-Attacken gegen den Firefox-Browser genutzt [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: United-Underground &#187; Mozilla Readies Firefox Patch</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-75266</link>
		<dc:creator>United-Underground &#187; Mozilla Readies Firefox Patch</dc:creator>
		<pubDate>Wed, 21 Nov 2007 22:00:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-75266</guid>
		<description>[...] of Jesse Ruderman, and gained widespread attention earlier this month when researcher Petko Petkov pointed out that the flaw could be used to launch a cross-site scripting attack against the Firefox browser. [...]</description>
		<content:encoded><![CDATA[<p>[...] of Jesse Ruderman, and gained widespread attention earlier this month when researcher Petko Petkov pointed out that the flaw could be used to launch a cross-site scripting attack against the Firefox browser. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Info World &#187; Blog Archive &#187; Firefox plans bug fix release for next week</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-75028</link>
		<dc:creator>Info World &#187; Blog Archive &#187; Firefox plans bug fix release for next week</dc:creator>
		<pubDate>Wed, 21 Nov 2007 11:59:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-75028</guid>
		<description>[...] Jesse Ruderman, but it gained widespread attention earlier this month when researcher Petko Petkov pointed out on his blog that the flaw could be used to launch a cross-site scripting attack against the Firefox [...]</description>
		<content:encoded><![CDATA[<p>[...] Jesse Ruderman, but it gained widespread attention earlier this month when researcher Petko Petkov pointed out on his blog that the flaw could be used to launch a cross-site scripting attack against the Firefox [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogZilla &#187; Falla &#34;JAR:&#34; per Firefox, XSS per Gmail</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-74966</link>
		<dc:creator>BlogZilla &#187; Falla &#34;JAR:&#34; per Firefox, XSS per Gmail</dc:creator>
		<pubDate>Wed, 21 Nov 2007 10:12:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-74966</guid>
		<description>[...] alcuni giorni si parla in rete di un nuovo problema di sicurezza critico che coinvolge la gestione del protocollo &quot;jar:&quot; da parte del browser Firefox sfruttabile [...]</description>
		<content:encoded><![CDATA[<p>[...] alcuni giorni si parla in rete di un nuovo problema di sicurezza critico che coinvolge la gestione del protocollo &quot;jar:&quot; da parte del browser Firefox sfruttabile [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Posiblemente tendremos el Firefox 2.0.0.10 para la semana que viene :</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-74950</link>
		<dc:creator>Posiblemente tendremos el Firefox 2.0.0.10 para la semana que viene :</dc:creator>
		<pubDate>Wed, 21 Nov 2007 09:40:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-74950</guid>
		<description>[...] ediciÃ³n segÃºn se ha comunicado soluciona algunos bugs, como el encontrado por Petko Petkov, que fue publicado en su blog el 7 de noviembre, en el que detectÃ³ una vulnerabilidad en que se [...]</description>
		<content:encoded><![CDATA[<p>[...] ediciÃ³n segÃºn se ha comunicado soluciona algunos bugs, como el encontrado por Petko Petkov, que fue publicado en su blog el 7 de noviembre, en el que detectÃ³ una vulnerabilidad en que se [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ICMPECHO &#187; Blog Archive &#187; Firefox JAR: vulnerability - quick summary</title>
		<link>http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues/comment-page-1/#comment-70890</link>
		<dc:creator>ICMPECHO &#187; Blog Archive &#187; Firefox JAR: vulnerability - quick summary</dc:creator>
		<pubDate>Thu, 15 Nov 2007 00:20:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues#comment-70890</guid>
		<description>[...] in the Mozilla bugzilla tracker. It remains unpatched and not widely known until&#8230;2007-11-07 - Researcher pdp discusses the issue and potential impact at GNUCitizen. This opens this bug up to a whole new audience and&#8230;2007-11-10 - Beford illustrates the [...]</description>
		<content:encoded><![CDATA[<p>[...] in the Mozilla bugzilla tracker. It remains unpatched and not widely known until&#8230;2007-11-07 &#8211; Researcher pdp discusses the issue and potential impact at GNUCitizen. This opens this bug up to a whole new audience and&#8230;2007-11-10 &#8211; Beford illustrates the [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
