<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Old NoScript Tricks Blocking New Vulnerabilities</title>
	<link>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Tue, 02 Dec 2008 12:50:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: hackademix.net » Clickjacking Protection By Default</title>
		<link>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-9465</link>
		<dc:creator>hackademix.net » Clickjacking Protection By Default</dc:creator>
		<pubDate>Thu, 02 Oct 2008 10:49:43 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-9465</guid>
		<description>[...] this feature had been introduced mainly to make Gareth Heyes happy, more than one year ago. As often observed with NoScript, an old feature happens to be effective against new threats. Unfortunately, bugs happen too and [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] this feature had been introduced mainly to make Gareth Heyes happy, more than one year ago. As often observed with NoScript, an old feature happens to be effective against new threats. Unfortunately, bugs happen too and [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-6746</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 04 Mar 2008 10:13:40 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-6746</guid>
		<description>@&lt;b&gt;Alexander Ciornii&lt;/b&gt;:
&lt;ol&gt;
&lt;li&gt;This was not that small. After an initial rating of "moderate", its security severity escalated to "high" because it actually allowed &lt;a href="https://bugzilla.mozilla.org/show_bug.cgi?id=413451" target="_blank" rel="nofollow external" rel="nofollow"&gt;reading the session store&lt;/a&gt; (where authenticated sessions are persisted), and therefore accessing your protected sites.&lt;/li&gt;
&lt;li&gt;If you read carefully the 2nd paragraph of my post, you'd know that NoScript blocks this and similar attacks no matter if the site is trusted or not, i.e. &lt;b&gt;you don't need to keep JavaScript on a certain site to be protected&lt;/b&gt;&lt;/li&gt;
&lt;/ol&gt;</description>
		<content:encoded><![CDATA[<p>@<b>Alexander Ciornii</b>:</p>
<ol>
<li>This was not that small. After an initial rating of &#8220;moderate&#8221;, its security severity escalated to &#8220;high&#8221; because it actually allowed <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=413451" target="_blank" rel="nofollow external" rel="nofollow">reading the session store</a> (where authenticated sessions are persisted), and therefore accessing your protected sites.</li>
<li>If you read carefully the 2nd paragraph of my post, you&#8217;d know that NoScript blocks this and similar attacks no matter if the site is trusted or not, i.e. <b>you don&#8217;t need to keep JavaScript on a certain site to be protected</b></li>
</ol>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexandr Ciornii</title>
		<link>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-6742</link>
		<dc:creator>Alexandr Ciornii</dc:creator>
		<pubDate>Tue, 04 Mar 2008 08:57:40 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-6742</guid>
		<description>Is this small vulnerability (allowing reading unimportant files) worth disabling JavaScript? I don't think so.</description>
		<content:encoded><![CDATA[<p>Is this small vulnerability (allowing reading unimportant files) worth disabling JavaScript? I don&#8217;t think so.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: clic</title>
		<link>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-6208</link>
		<dc:creator>clic</dc:creator>
		<pubDate>Tue, 19 Feb 2008 10:24:42 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-6208</guid>
		<description>Grande estensione, è la prima che scarico per firefox quando ho un computer fresh-install ;) - complimenti</description>
		<content:encoded><![CDATA[<p>Grande estensione, è la prima che scarico per firefox quando ho un computer fresh-install ;) - complimenti</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vinicius K-Max</title>
		<link>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-5283</link>
		<dc:creator>Vinicius K-Max</dc:creator>
		<pubDate>Tue, 29 Jan 2008 03:59:58 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-5283</guid>
		<description>NOScript is the best!</description>
		<content:encoded><![CDATA[<p>NOScript is the best!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknico&#8217;s Blog &#187; Firefox: Falla Chrome Directory Traversal</title>
		<link>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-5116</link>
		<dc:creator>Darknico&#8217;s Blog &#187; Firefox: Falla Chrome Directory Traversal</dc:creator>
		<pubDate>Fri, 25 Jan 2008 13:31:31 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-5116</guid>
		<description>[...] Come riporta Giorgio Maone, autore di geek italiano e autore di popolari estensioni per Firefox come FlashGot e NoScript, la potente estensione di sicurezza NoScript è in grado di impedire agli URI chrome di essere caricati come script nei contenuti web, rendendo così questo bug impossibile da sfruttare, indipendentemente dal fatto che il sito dell&#8217;attacker sia impostato come sicuro (cioè gli sia permessa l&#8217;esecuzione di codice JavaScript). [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Come riporta Giorgio Maone, autore di geek italiano e autore di popolari estensioni per Firefox come FlashGot e NoScript, la potente estensione di sicurezza NoScript è in grado di impedire agli URI chrome di essere caricati come script nei contenuti web, rendendo così questo bug impossibile da sfruttare, indipendentemente dal fatto che il sito dell&#8217;attacker sia impostato come sicuro (cioè gli sia permessa l&#8217;esecuzione di codice JavaScript). [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco Ramilli</title>
		<link>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-5048</link>
		<dc:creator>Marco Ramilli</dc:creator>
		<pubDate>Wed, 23 Jan 2008 18:27:27 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-5048</guid>
		<description>Yes, good job !!
I've always believed that NoScript was an useful toll but now my believe is much more strong !</description>
		<content:encoded><![CDATA[<p>Yes, good job !!<br />
I&#8217;ve always believed that NoScript was an useful toll but now my believe is much more strong !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-5047</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Wed, 23 Jan 2008 16:32:01 +0000</pubDate>
		<guid>http://hackademix.net/2008/01/23/old-noscript-tricks-blocking-new-vulnerabilities/#comment-5047</guid>
		<description>Awesome work as always Giorgio!</description>
		<content:encoded><![CDATA[<p>Awesome work as always Giorgio!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
