<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: GMail POST Mortem, CSRF Countermeasures and NoScript Misconceptions</title>
	<link>http://hackademix.net/2007/09/26/gmail_csrf/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Sat, 31 Jul 2010 04:29:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Club Penguin Cheats</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-19488</link>
		<dc:creator>Club Penguin Cheats</dc:creator>
		<pubDate>Sun, 17 Jan 2010 02:25:49 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-19488</guid>
		<description>Don’t get me wrong. NoScript is one of the best things that have happened to Firefox and my and the rest of the community truly appreciate the work that has bee done. But also, I have to say that normal users will hate it in their guts mainly because it makes their MySpace page not working. We know that we cannot make regular users security experts just so they don’t get hacked. They have other problems to worry about. The only proven way of protecting them is to write secure software. But again, that will never happen.</description>
		<content:encoded><![CDATA[<p>Don’t get me wrong. NoScript is one of the best things that have happened to Firefox and my and the rest of the community truly appreciate the work that has bee done. But also, I have to say that normal users will hate it in their guts mainly because it makes their MySpace page not working. We know that we cannot make regular users security experts just so they don’t get hacked. They have other problems to worry about. The only proven way of protecting them is to write secure software. But again, that will never happen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » Browser Plugins, Add-Ons and Security Advisers</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-10828</link>
		<dc:creator>hackademix.net » Browser Plugins, Add-Ons and Security Advisers</dc:creator>
		<pubDate>Sun, 08 Feb 2009 01:06:38 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-10828</guid>
		<description>[...] I choose qmail for my example because of its almost immaculate security records: should you pick a single product to illustrate mail server security risks, you’d bash Sendmail with its several documented vulnerabilities, rather than DJB’s impervious creature. However the article inexplicably morphed “qmail” into GMail, making my point quite obscure (given that GMail is not even a proper mail server, nor exactly a security champion). [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] I choose qmail for my example because of its almost immaculate security records: should you pick a single product to illustrate mail server security risks, you’d bash Sendmail with its several documented vulnerabilities, rather than DJB’s impervious creature. However the article inexplicably morphed “qmail” into GMail, making my point quite obscure (given that GMail is not even a proper mail server, nor exactly a security champion). [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google Gmail E-mail Hijack &#124; keyongtech</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-10536</link>
		<dc:creator>Google Gmail E-mail Hijack &#124; keyongtech</dc:creator>
		<pubDate>Thu, 22 Jan 2009 00:56:28 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-10536</guid>
		<description>[...] Use Firefox with No-Script: GMail POST Mortem, CSRF Countermeasures and NoScript Misconceptions: http://hackademix.net/2007/09/26/gmail_csrf/  [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Use Firefox with No-Script: GMail POST Mortem, CSRF Countermeasures and NoScript Misconceptions: <a href="http://hackademix.net/2007/09/26/gmail_csrf/" rel="nofollow">http://hackademix.net/2007/09/26/gmail_csrf/</a>  [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » Petko Was Playing With Fire...</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-8989</link>
		<dc:creator>hackademix.net » Petko Was Playing With Fire...</dc:creator>
		<pubDate>Wed, 13 Aug 2008 23:13:30 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-8989</guid>
		<description>[...] if Petko is right, a certain comment of his about NoScript, posted under an article about GMail attacks (!) almost one year ago, sounds totally ironic now [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] if Petko is right, a certain comment of his about NoScript, posted under an article about GMail attacks (!) almost one year ago, sounds totally ironic now [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ninjas</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-1677</link>
		<dc:creator>Ninjas</dc:creator>
		<pubDate>Wed, 21 Nov 2007 21:49:33 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-1677</guid>
		<description>Nice link power!

http://http//hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/

WOO!</description>
		<content:encoded><![CDATA[<p>Nice link power!</p>
<p><a href="http://http//hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/" rel="nofollow">http://http//hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/</a></p>
<p>WOO!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alessandro</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-550</link>
		<dc:creator>Alessandro</dc:creator>
		<pubDate>Sat, 29 Sep 2007 14:22:55 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-550</guid>
		<description>Hi Giorgio!
I follow you and your posts from many time. I appreciate your Firefox extension, NoScript, and I suggest its use to all my friends.

I work in information security and I can affirm that your extension works fine..It has been tested to arginate several web attack attempt and passes in honest way. 

Great.</description>
		<content:encoded><![CDATA[<p>Hi Giorgio!<br />
I follow you and your posts from many time. I appreciate your Firefox extension, NoScript, and I suggest its use to all my friends.</p>
<p>I work in information security and I can affirm that your extension works fine..It has been tested to arginate several web attack attempt and passes in honest way. </p>
<p>Great.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-531</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Fri, 28 Sep 2007 13:31:02 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-531</guid>
		<description>@&lt;b&gt;sirdarckcat&lt;/b&gt;:
Yours is subtle yet scary.
If we count all them I'm afraid there are a few more than 5, but I'll better wait the week end to do an ultimate recap ;)</description>
		<content:encoded><![CDATA[<p>@<b>sirdarckcat</b>:<br />
Yours is subtle yet scary.<br />
If we count all them I&#8217;m afraid there are a few more than 5, but I&#8217;ll better wait the week end to do an ultimate recap ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-530</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Fri, 28 Sep 2007 12:54:14 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-530</guid>
		<description>Cool :P
now there are 5 Google vulns hehe
http://sirdarckcat.blogspot.com/2007/09/google-mashups-vulnerability.html

let's say this is a historic event.. I submited a similar comment to xs-sniper, but it showed a Forbidden error.. :S

Greetz!!</description>
		<content:encoded><![CDATA[<p>Cool :P<br />
now there are 5 Google vulns hehe<br />
<a href="http://sirdarckcat.blogspot.com/2007/09/google-mashups-vulnerability.html" rel="nofollow">http://sirdarckcat.blogspot.com/2007/09/google-mashups-vulnerability.html</a></p>
<p>let&#8217;s say this is a historic event.. I submited a similar comment to xs-sniper, but it showed a Forbidden error.. :S</p>
<p>Greetz!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google Gmail: &#8220;E-mail Hijack&#8221; via CSRF &#171; Simply Security</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-526</link>
		<dc:creator>Google Gmail: &#8220;E-mail Hijack&#8221; via CSRF &#171; Simply Security</dc:creator>
		<pubDate>Fri, 28 Sep 2007 08:01:25 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-526</guid>
		<description>[...] XSS, od anche contro le recenti popolari vulnerabilità dei gestori URI. Consigliamo a tutti di leggere interamente l&#8217;intervento di Maone che offre numerosi dettagli sulle potenzialità di [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] XSS, od anche contro le recenti popolari vulnerabilità dei gestori URI. Consigliamo a tutti di leggere interamente l&#8217;intervento di Maone che offre numerosi dettagli sulle potenzialità di [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://hackademix.net/2007/09/26/gmail_csrf/#comment-498</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 27 Sep 2007 03:05:24 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/26/gmail_csrf/#comment-498</guid>
		<description>don't get me wrong, Giorgio work is highly appreciated, all I am saying is that users don't have to be experts in order to know what sites should be able to use scripts. How do u trust a site? If it looks good? In order to trust the application that you are about to grant some permissions you have to really know what you are doing. In that case, how does this helps the normal user? They have to check the source code? It does help if you are visiting some doggy cracking sites and you expect to be hit any moment so u need to put your shields up, but for normal surfing... I don't know man. The web is changing drastically if you haven't noticed. Websites are almost like desktop applications. Do you have an warning from your Ant-vir every time you try to run an app? No! They try to mitigate the problem before warning you, if there is one.

And what about mashups? I mean, mashups are just combination of a bunch of services. So in order to run the stupid Google Maps you have to approve all websites the mashup is feeding from or interacting with? This is only for experienced surfers and web dev guys. Anyway, again, great work Giorgio. It is always good to get a different opinion. It helps you see the bigger picture sometimes.

As a security expert, I am supposed to preach about Application Firewalls, NoScript, IDSs, etc, but I don't. It is not just black and white. It is all about risk management. You cannot say to someone install this and your problem will be solved. It doesn't work this way.

Keep it up.</description>
		<content:encoded><![CDATA[<p>don&#8217;t get me wrong, Giorgio work is highly appreciated, all I am saying is that users don&#8217;t have to be experts in order to know what sites should be able to use scripts. How do u trust a site? If it looks good? In order to trust the application that you are about to grant some permissions you have to really know what you are doing. In that case, how does this helps the normal user? They have to check the source code? It does help if you are visiting some doggy cracking sites and you expect to be hit any moment so u need to put your shields up, but for normal surfing&#8230; I don&#8217;t know man. The web is changing drastically if you haven&#8217;t noticed. Websites are almost like desktop applications. Do you have an warning from your Ant-vir every time you try to run an app? No! They try to mitigate the problem before warning you, if there is one.</p>
<p>And what about mashups? I mean, mashups are just combination of a bunch of services. So in order to run the stupid Google Maps you have to approve all websites the mashup is feeding from or interacting with? This is only for experienced surfers and web dev guys. Anyway, again, great work Giorgio. It is always good to get a different opinion. It helps you see the bigger picture sometimes.</p>
<p>As a security expert, I am supposed to preach about Application Firewalls, NoScript, IDSs, etc, but I don&#8217;t. It is not just black and white. It is all about risk management. You cannot say to someone install this and your problem will be solved. It doesn&#8217;t work this way.</p>
<p>Keep it up.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
