<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Mikeyy&#8217;s StalkDaily Twitter Worm vs NoScript</title>
	<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 08 Feb 2012 12:22:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Twitter Trackbacks for hackademix.net » Mikeyy's StalkDaily Twitter Worm vs NoScript [hackademix.net] on Topsy.com</title>
		<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-14468</link>
		<dc:creator>Twitter Trackbacks for hackademix.net » Mikeyy's StalkDaily Twitter Worm vs NoScript [hackademix.net] on Topsy.com</dc:creator>
		<pubDate>Sat, 29 Aug 2009 23:16:24 +0000</pubDate>
		<guid>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-14468</guid>
		<description>[...] hackademix.net » Mikeyy's StalkDaily Twitter Worm vs NoScript  hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript – view page – cached  Giorgio Maone’s answers to the Web, the Universe, and Everything * Home * Why * Me, ma1 — From the page [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] hackademix.net » Mikeyy&#8217;s StalkDaily Twitter Worm vs NoScript  hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript – view page – cached  Giorgio Maone’s answers to the Web, the Universe, and Everything * Home * Why * Me, ma1 — From the page [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jake Kasprzak Online › The Twitter XSS Worm and Lessons That Can Be Learned From It</title>
		<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-12081</link>
		<dc:creator>Jake Kasprzak Online › The Twitter XSS Worm and Lessons That Can Be Learned From It</dc:creator>
		<pubDate>Mon, 27 Apr 2009 23:52:15 +0000</pubDate>
		<guid>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-12081</guid>
		<description>[...] here, is a modified yet non-obfuscated version of the source code used by the original worm. As Giorgio Maone said, it appeared as if those trying to correct this issue were trying to defend again.... A few days after this was mentioned, Lynne Pope mentioned that with variations of the worm [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] here, is a modified yet non-obfuscated version of the source code used by the original worm. As Giorgio Maone said, it appeared as if those trying to correct this issue were trying to defend again&#8230;. A few days after this was mentioned, Lynne Pope mentioned that with variations of the worm [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom  T.</title>
		<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11929</link>
		<dc:creator>Tom  T.</dc:creator>
		<pubDate>Tue, 14 Apr 2009 21:43:18 +0000</pubDate>
		<guid>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11929</guid>
		<description>#9  Giorgio says:
April 14th, 2009 at 12:18 pm

@Tom T.:
I believe there’s a little misunderstanding here. What therube means, I guess, is that most NoScript users keep the default (medium lockdown) configuration, i.e. they’ve got “Base 2nd level Domains” checked in the Appearance options...

#12:
However most tech savvy users do understand this issue and switch “Full domains” or “Full address” view (I use the former, and I guess therube does as well)

Yes, my misunderstanding. I assumed &lt;b&gt;therube&lt;/b&gt; was referring to the &lt;i&gt;General&lt;/i&gt; tab, &#34;Temp Allow ... by default&#34; (Full, Base 2nd, etc.), rather than the &lt;i&gt;Appearance&lt;/i&gt; tab. FWIW, I do have &#34;Full address&#34; view selected there. Thanks for clearing up my misunderstanding.</description>
		<content:encoded><![CDATA[<p>#9  Giorgio says:<br />
April 14th, 2009 at 12:18 pm</p>
<p>@Tom T.:<br />
I believe there’s a little misunderstanding here. What therube means, I guess, is that most NoScript users keep the default (medium lockdown) configuration, i.e. they’ve got “Base 2nd level Domains” checked in the Appearance options&#8230;</p>
<p>#12:<br />
However most tech savvy users do understand this issue and switch “Full domains” or “Full address” view (I use the former, and I guess therube does as well)</p>
<p>Yes, my misunderstanding. I assumed <b>therube</b> was referring to the <i>General</i> tab, &quot;Temp Allow &#8230; by default&quot; (Full, Base 2nd, etc.), rather than the <i>Appearance</i> tab. FWIW, I do have &quot;Full address&quot; view selected there. Thanks for clearing up my misunderstanding.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11926</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 14 Apr 2009 18:41:59 +0000</pubDate>
		<guid>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11926</guid>
		<description>@&lt;b&gt;duryodhan&lt;/b&gt;:
for the sake of usability. NoScript is aimed to the average user, despite some dissenting voices, and you need to draw the line somewhere: on some sites the number of menu items is already overwhelming by default, and the choice can be hard and time consuming.

However most tech savvy users do understand this issue and switch "Full domains" or "Full address" view (I use the former, and I guess therube does as well).</description>
		<content:encoded><![CDATA[<p>@<b>duryodhan</b>:<br />
for the sake of usability. NoScript is aimed to the average user, despite some dissenting voices, and you need to draw the line somewhere: on some sites the number of menu items is already overwhelming by default, and the choice can be hard and time consuming.</p>
<p>However most tech savvy users do understand this issue and switch &#8220;Full domains&#8221; or &#8220;Full address&#8221; view (I use the former, and I guess therube does as well).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: duryodhan</title>
		<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11925</link>
		<dc:creator>duryodhan</dc:creator>
		<pubDate>Tue, 14 Apr 2009 18:28:01 +0000</pubDate>
		<guid>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11925</guid>
		<description>Hmm .. he does raise a good point though...  is there any way to host a js on Google.com / Yahoo.com etc. subdomain?

Any particular use cases why &#34;Base 2nd level domains&#34; is the default?</description>
		<content:encoded><![CDATA[<p>Hmm .. he does raise a good point though&#8230;  is there any way to host a js on Google.com / Yahoo.com etc. subdomain?</p>
<p>Any particular use cases why &quot;Base 2nd level domains&quot; is the default?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Web worm infetta Twitter: di cosa si tratta? - Appunti Digitali</title>
		<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11921</link>
		<dc:creator>Web worm infetta Twitter: di cosa si tratta? - Appunti Digitali</dc:creator>
		<pubDate>Tue, 14 Apr 2009 11:00:43 +0000</pubDate>
		<guid>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11921</guid>
		<description>[...] le raccomandazioni sono sempre le stesse: tenere sempre la guardia alta e usare plugins come NoScript. Gli sviluppatori web, dal canto loro, dovrebbero seguire con cura le linee guida indicate da OWASP [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] le raccomandazioni sono sempre le stesse: tenere sempre la guardia alta e usare plugins come NoScript. Gli sviluppatori web, dal canto loro, dovrebbero seguire con cura le linee guida indicate da OWASP [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11918</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 14 Apr 2009 10:18:25 +0000</pubDate>
		<guid>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11918</guid>
		<description>@&lt;b&gt;Tom T.&lt;/b&gt;:
I believe there's a little misunderstanding here. What &lt;b&gt;therube&lt;/b&gt; means, I guess, is that most NoScript users keep the default (medium lockdown) configuration, i.e. they've got "Base 2&lt;sup&gt;nd&lt;/sup&gt; level Domains" checked in the &lt;em&gt;Appearance&lt;/em&gt; options. This doesn't mean they've got anything &lt;em&gt;allowed&lt;/em&gt; by default, this just means that when they popup NoScript's menu they can see 2&lt;sup&gt;nd&lt;/sup&gt; level domains (like &lt;em&gt;uuuq.com&lt;/em&gt;) rather than full domains (&lt;em&gt;mikeyy.uuuq.com&lt;/em&gt;. However it's just as unlikely that any NoScript user has &lt;em&gt;uuuq.com&lt;/em&gt; in his/her (permanent) whitelist.</description>
		<content:encoded><![CDATA[<p>@<b>Tom T.</b>:<br />
I believe there&#8217;s a little misunderstanding here. What <b>therube</b> means, I guess, is that most NoScript users keep the default (medium lockdown) configuration, i.e. they&#8217;ve got &#8220;Base 2<sup>nd</sup> level Domains&#8221; checked in the <em>Appearance</em> options. This doesn&#8217;t mean they&#8217;ve got anything <em>allowed</em> by default, this just means that when they popup NoScript&#8217;s menu they can see 2<sup>nd</sup> level domains (like <em>uuuq.com</em>) rather than full domains (<em>mikeyy.uuuq.com</em>. However it&#8217;s just as unlikely that any NoScript user has <em>uuuq.com</em> in his/her (permanent) whitelist.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Day mobile edition</title>
		<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11916</link>
		<dc:creator>Zero Day mobile edition</dc:creator>
		<pubDate>Tue, 14 Apr 2009 09:19:27 +0000</pubDate>
		<guid>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11916</guid>
		<description>[...] campaigns.  With the proof of concept code for both of the worms now publicly available, and with NoScript's creator Giorgio Maone logical conclusion that Twitter may have in fact not taken care of the XSS flaw as the second variant launched by a [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] campaigns.  With the proof of concept code for both of the worms now publicly available, and with NoScript&#8217;s creator Giorgio Maone logical conclusion that Twitter may have in fact not taken care of the XSS flaw as the second variant launched by a [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom  T.</title>
		<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11910</link>
		<dc:creator>Tom  T.</dc:creator>
		<pubDate>Tue, 14 Apr 2009 04:11:56 +0000</pubDate>
		<guid>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11910</guid>
		<description>therube wrote:

&#34;Going on the assumption that the majority of NoScript users have (the default) ‘Base 2nd level Domains’ enabled,&#34;

Ever since the decision to default to full lockdown of ClearClick protection (trusted and un-), I had assumed that full lockdown  was the default on all. We are telling people, &#34;Everything is blacklisted by default&#34;. I've always run that way.
http://img21.imageshack.us/img21/884/nslockdown.png
If *any* levels of domains are allowed by default, perhaps that decision should be reconsidered, or we should warn people and amend the FAQ, Beginner's Guide, etc. accordingly.</description>
		<content:encoded><![CDATA[<p>therube wrote:</p>
<p>&quot;Going on the assumption that the majority of NoScript users have (the default) ‘Base 2nd level Domains’ enabled,&quot;</p>
<p>Ever since the decision to default to full lockdown of ClearClick protection (trusted and un-), I had assumed that full lockdown  was the default on all. We are telling people, &quot;Everything is blacklisted by default&quot;. I&#8217;ve always run that way.<br />
<a href="http://img21.imageshack.us/img21/884/nslockdown.png" rel="nofollow">http://img21.imageshack.us/img21/884/nslockdown.png</a><br />
If *any* levels of domains are allowed by default, perhaps that decision should be reconsidered, or we should warn people and amend the FAQ, Beginner&#8217;s Guide, etc. accordingly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GµårÐïåñ</title>
		<link>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11899</link>
		<dc:creator>GµårÐïåñ</dc:creator>
		<pubDate>Mon, 13 Apr 2009 20:47:20 +0000</pubDate>
		<guid>http://hackademix.net/2009/04/13/mikeyys-stalkdaily-twitter-worm-vs-noscript/#comment-11899</guid>
		<description>Well as I always say, stop chasing fads, use common sense, and try to take a pessimistic approach to the web and protect yourself proactively. Always knew NoScript rocks, now the proof is in the pudding :)</description>
		<content:encoded><![CDATA[<p>Well as I always say, stop chasing fads, use common sense, and try to take a pessimistic approach to the web and protect yourself proactively. Always knew NoScript rocks, now the proof is in the pudding :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

