<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Flash XSS Protection For Users</title>
	<link>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Mon, 12 May 2008 16:28:38 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: TikaL</title>
		<link>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/#comment-5714</link>
		<dc:creator>TikaL</dc:creator>
		<pubDate>Fri, 08 Feb 2008 11:56:01 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/#comment-5714</guid>
		<description>@Giorgio:

Thanks for the clarification.</description>
		<content:encoded><![CDATA[<p>@Giorgio:</p>
<p>Thanks for the clarification.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/#comment-5644</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Wed, 06 Feb 2008 14:02:07 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/#comment-5644</guid>
		<description>@&lt;b&gt;TikaL&lt;/b&gt;:
Flash XSS can do anything a "traditional" JavaScript &lt;a href="http://en.wikipedia.org/wiki/Cross-site_scripting" rel="nofollow external" target="_blank" rel="nofollow"&gt;XSS&lt;/a&gt; can do, from credential theft to session riding (impersonating yourself across the current session) to complex &lt;a href="http://en.wikipedia.org/wiki/CSRF" rel="nofollow external" target="_blank" rel="nofollow"&gt;CSRF&lt;/a&gt; despite anti-CSRF protections which may be implemented on the target web site.</description>
		<content:encoded><![CDATA[<p>@<b>TikaL</b>:<br />
Flash XSS can do anything a &#8220;traditional&#8221; JavaScript <a href="http://en.wikipedia.org/wiki/Cross-site_scripting" rel="nofollow external" target="_blank" rel="nofollow">XSS</a> can do, from credential theft to session riding (impersonating yourself across the current session) to complex <a href="http://en.wikipedia.org/wiki/CSRF" rel="nofollow external" target="_blank" rel="nofollow">CSRF</a> despite anti-CSRF protections which may be implemented on the target web site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TikaL</title>
		<link>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/#comment-5605</link>
		<dc:creator>TikaL</dc:creator>
		<pubDate>Tue, 05 Feb 2008 10:50:55 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/#comment-5605</guid>
		<description>I wanted to know what kind of damage can be done by this type of intrusion? I use Flash on almost a daily basis. i Might not be keeping up with what can be done... but this is interesting to me.


Thanks,

TikaL</description>
		<content:encoded><![CDATA[<p>I wanted to know what kind of damage can be done by this type of intrusion? I use Flash on almost a daily basis. i Might not be keeping up with what can be done&#8230; but this is interesting to me.</p>
<p>Thanks,</p>
<p>TikaL</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/#comment-4498</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sat, 12 Jan 2008 06:21:27 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/#comment-4498</guid>
		<description>@&lt;b&gt;Mobile&lt;/b&gt;:
You just need to click on the placeholder for the document -- after all, you're most likely going to click on the document itself anyway, e.g. for scrolling it.

However, an exception list for the &lt;em&gt;Forbid Other Plugins&lt;/em&gt; options (which, if checked, is currently catching PDFs too) is definitely coming in a future release.</description>
		<content:encoded><![CDATA[<p>@<b>Mobile</b>:<br />
You just need to click on the placeholder for the document &#8212; after all, you&#8217;re most likely going to click on the document itself anyway, e.g. for scrolling it.</p>
<p>However, an exception list for the <em>Forbid Other Plugins</em> options (which, if checked, is currently catching PDFs too) is definitely coming in a future release.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mobile</title>
		<link>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/#comment-4491</link>
		<dc:creator>Mobile</dc:creator>
		<pubDate>Fri, 11 Jan 2008 20:59:44 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/06/flash-xss-protection-for-users/#comment-4491</guid>
		<description>I'm an avid user of Noscript, the program designed for firefox.

Well, since some Noscript updates that were installed, I noticed that embedded Adobe pdf files were disabled by default. Browsing through the Nosctipt options, I saw that Adobe flash extensions were untrusted.

As a student, using the internet as a source of information is very necessary and i encounter adobe pdf files very often. So, may I request that Noscript has a seperate choice for adobe pdfs in some future updates? cause it would be great for me, and I will not have to click "allow" all the time. I'm also sure that there are many users out there that will share my inconvenience. 

Thank you for listening to some irritating person,

Yours.</description>
		<content:encoded><![CDATA[<p>I&#8217;m an avid user of Noscript, the program designed for firefox.</p>
<p>Well, since some Noscript updates that were installed, I noticed that embedded Adobe pdf files were disabled by default. Browsing through the Nosctipt options, I saw that Adobe flash extensions were untrusted.</p>
<p>As a student, using the internet as a source of information is very necessary and i encounter adobe pdf files very often. So, may I request that Noscript has a seperate choice for adobe pdfs in some future updates? cause it would be great for me, and I will not have to click &#8220;allow&#8221; all the time. I&#8217;m also sure that there are many users out there that will share my inconvenience. </p>
<p>Thank you for listening to some irritating person,</p>
<p>Yours.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
