<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: GMail POST Mortem, CSRF Countermeasures and NoScript Misconceptions</title>
	<link>http://hackademix.net/2007/09/26/gmail_csrf/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Tue, 02 Dec 2008 12:45:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: hackademix.net » Petko Was Playing With Fire...</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-8989</link>
		<dc:creator>hackademix.net » Petko Was Playing With Fire...</dc:creator>
		<pubDate>Wed, 13 Aug 2008 23:13:30 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-8989</guid>
		<description>[...] if Petko is right, a certain comment of his about NoScript, posted under an article about GMail attacks (!) almost one year ago, sounds totally ironic now [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] if Petko is right, a certain comment of his about NoScript, posted under an article about GMail attacks (!) almost one year ago, sounds totally ironic now [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ninjas</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-1677</link>
		<dc:creator>Ninjas</dc:creator>
		<pubDate>Wed, 21 Nov 2007 21:49:33 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-1677</guid>
		<description>Nice link power!

http://http//hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/

WOO!</description>
		<content:encoded><![CDATA[<p>Nice link power!</p>
<p><a href="http://http//hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/" rel="nofollow">http://http//hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/</a></p>
<p>WOO!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alessandro</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-550</link>
		<dc:creator>Alessandro</dc:creator>
		<pubDate>Sat, 29 Sep 2007 14:22:55 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-550</guid>
		<description>Hi Giorgio!
I follow you and your posts from many time. I appreciate your Firefox extension, NoScript, and I suggest its use to all my friends.

I work in information security and I can affirm that your extension works fine..It has been tested to arginate several web attack attempt and passes in honest way. 

Great.</description>
		<content:encoded><![CDATA[<p>Hi Giorgio!<br />
I follow you and your posts from many time. I appreciate your Firefox extension, NoScript, and I suggest its use to all my friends.</p>
<p>I work in information security and I can affirm that your extension works fine..It has been tested to arginate several web attack attempt and passes in honest way. </p>
<p>Great.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-531</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Fri, 28 Sep 2007 13:31:02 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-531</guid>
		<description>@&lt;b&gt;sirdarckcat&lt;/b&gt;:
Yours is subtle yet scary.
If we count all them I'm afraid there are a few more than 5, but I'll better wait the week end to do an ultimate recap ;)</description>
		<content:encoded><![CDATA[<p>@<b>sirdarckcat</b>:<br />
Yours is subtle yet scary.<br />
If we count all them I&#8217;m afraid there are a few more than 5, but I&#8217;ll better wait the week end to do an ultimate recap ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-530</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Fri, 28 Sep 2007 12:54:14 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-530</guid>
		<description>Cool :P
now there are 5 Google vulns hehe
http://sirdarckcat.blogspot.com/2007/09/google-mashups-vulnerability.html

let's say this is a historic event.. I submited a similar comment to xs-sniper, but it showed a Forbidden error.. :S

Greetz!!</description>
		<content:encoded><![CDATA[<p>Cool :P<br />
now there are 5 Google vulns hehe<br />
<a href="http://sirdarckcat.blogspot.com/2007/09/google-mashups-vulnerability.html" rel="nofollow">http://sirdarckcat.blogspot.com/2007/09/google-mashups-vulnerability.html</a></p>
<p>let&#8217;s say this is a historic event.. I submited a similar comment to xs-sniper, but it showed a Forbidden error.. :S</p>
<p>Greetz!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google Gmail: &#8220;E-mail Hijack&#8221; via CSRF &#171; Simply Security</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-526</link>
		<dc:creator>Google Gmail: &#8220;E-mail Hijack&#8221; via CSRF &#171; Simply Security</dc:creator>
		<pubDate>Fri, 28 Sep 2007 08:01:25 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-526</guid>
		<description>[...] XSS, od anche contro le recenti popolari vulnerabilità dei gestori URI. Consigliamo a tutti di leggere interamente l&#8217;intervento di Maone che offre numerosi dettagli sulle potenzialità di [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] XSS, od anche contro le recenti popolari vulnerabilità dei gestori URI. Consigliamo a tutti di leggere interamente l&#8217;intervento di Maone che offre numerosi dettagli sulle potenzialità di [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-498</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 27 Sep 2007 03:05:24 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-498</guid>
		<description>don't get me wrong, Giorgio work is highly appreciated, all I am saying is that users don't have to be experts in order to know what sites should be able to use scripts. How do u trust a site? If it looks good? In order to trust the application that you are about to grant some permissions you have to really know what you are doing. In that case, how does this helps the normal user? They have to check the source code? It does help if you are visiting some doggy cracking sites and you expect to be hit any moment so u need to put your shields up, but for normal surfing... I don't know man. The web is changing drastically if you haven't noticed. Websites are almost like desktop applications. Do you have an warning from your Ant-vir every time you try to run an app? No! They try to mitigate the problem before warning you, if there is one.

And what about mashups? I mean, mashups are just combination of a bunch of services. So in order to run the stupid Google Maps you have to approve all websites the mashup is feeding from or interacting with? This is only for experienced surfers and web dev guys. Anyway, again, great work Giorgio. It is always good to get a different opinion. It helps you see the bigger picture sometimes.

As a security expert, I am supposed to preach about Application Firewalls, NoScript, IDSs, etc, but I don't. It is not just black and white. It is all about risk management. You cannot say to someone install this and your problem will be solved. It doesn't work this way.

Keep it up.</description>
		<content:encoded><![CDATA[<p>don&#8217;t get me wrong, Giorgio work is highly appreciated, all I am saying is that users don&#8217;t have to be experts in order to know what sites should be able to use scripts. How do u trust a site? If it looks good? In order to trust the application that you are about to grant some permissions you have to really know what you are doing. In that case, how does this helps the normal user? They have to check the source code? It does help if you are visiting some doggy cracking sites and you expect to be hit any moment so u need to put your shields up, but for normal surfing&#8230; I don&#8217;t know man. The web is changing drastically if you haven&#8217;t noticed. Websites are almost like desktop applications. Do you have an warning from your Ant-vir every time you try to run an app? No! They try to mitigate the problem before warning you, if there is one.</p>
<p>And what about mashups? I mean, mashups are just combination of a bunch of services. So in order to run the stupid Google Maps you have to approve all websites the mashup is feeding from or interacting with? This is only for experienced surfers and web dev guys. Anyway, again, great work Giorgio. It is always good to get a different opinion. It helps you see the bigger picture sometimes.</p>
<p>As a security expert, I am supposed to preach about Application Firewalls, NoScript, IDSs, etc, but I don&#8217;t. It is not just black and white. It is all about risk management. You cannot say to someone install this and your problem will be solved. It doesn&#8217;t work this way.</p>
<p>Keep it up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nap</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-489</link>
		<dc:creator>nap</dc:creator>
		<pubDate>Wed, 26 Sep 2007 16:55:54 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-489</guid>
		<description>NoScript is certainly not like firebug (i use both). I've been using it for months for "technologically savvy" uses, but soon I realized that anybody can benefit of using it - with scripts globally allowed- to increase security while maintaining usability. It is certainly an add-on everybody can benefit from.</description>
		<content:encoded><![CDATA[<p>NoScript is certainly not like firebug (i use both). I&#8217;ve been using it for months for &#8220;technologically savvy&#8221; uses, but soon I realized that anybody can benefit of using it - with scripts globally allowed- to increase security while maintaining usability. It is certainly an add-on everybody can benefit from.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-487</link>
		<dc:creator>Jordan</dc:creator>
		<pubDate>Wed, 26 Sep 2007 16:39:50 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-487</guid>
		<description>I installed NoScript on my wife's computer.  She's by no means a geek, and she makes do with it.

Also, no, it doesn't really break much of anything since I've used NoScript with that option for quite some time without problems.  

I know Giorgio sounds like he's doing PR for a company for as many times as he writes about NoScript, but he deserves to.  He really puts so much work into maintaining it and adding great features, and it's easily my number one firefox extension.  

Now's as good of a time as any to say thanks, I suppose!</description>
		<content:encoded><![CDATA[<p>I installed NoScript on my wife&#8217;s computer.  She&#8217;s by no means a geek, and she makes do with it.</p>
<p>Also, no, it doesn&#8217;t really break much of anything since I&#8217;ve used NoScript with that option for quite some time without problems.  </p>
<p>I know Giorgio sounds like he&#8217;s doing PR for a company for as many times as he writes about NoScript, but he deserves to.  He really puts so much work into maintaining it and adding great features, and it&#8217;s easily my number one firefox extension.  </p>
<p>Now&#8217;s as good of a time as any to say thanks, I suppose!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-483</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 26 Sep 2007 12:28:39 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-483</guid>
		<description>"No, she doesn’t, but she’s got NoScript — and her mom too…"

:) heh.. nice one...</description>
		<content:encoded><![CDATA[<p>&#8220;No, she doesn’t, but she’s got NoScript — and her mom too…&#8221;</p>
<p>:) heh.. nice one&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
