<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: IE&#8217;s XSS Filter Creates XSS Vulnerabilities</title>
	<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Mon, 15 Mar 2010 20:18:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Jess</title>
		<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-21905</link>
		<dc:creator>Jess</dc:creator>
		<pubDate>Wed, 24 Feb 2010 23:51:35 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-21905</guid>
		<description>As for me, I am using this tool for preventing XSS disasters:
http://xss-scanner.com</description>
		<content:encoded><![CDATA[<p>As for me, I am using this tool for preventing XSS disasters:<br />
<a href="http://xss-scanner.com" rel="nofollow">http://xss-scanner.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom T.</title>
		<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16336</link>
		<dc:creator>Tom T.</dc:creator>
		<pubDate>Fri, 27 Nov 2009 09:49:09 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16336</guid>
		<description>@ #14: My Arabic is a little more rusty than my German, but it looks like the headline is: 

Technical magazine: Non-secure IE 8 across XSS as a means of protection against attacks

From the article: 

&#34;NoScript is in disagreement with the add-on in IE8.
It analyses answers server and not requests for users, which could be the attackers of manipulation of answers server and injection certain codes for its implementation, Giorgio Maone says.

&#34;And who did not disclose the details of the matter is that the whole matter is based on an error in the basic design, which should be reconsidered in the design, Maone adds.&#34;

Pretty bad translation -- I know people who could do better -- but the bottom line comes out the same in any language. Looks like the whole world knows the story. :-)</description>
		<content:encoded><![CDATA[<p>@ #14: My Arabic is a little more rusty than my German, but it looks like the headline is: </p>
<p>Technical magazine: Non-secure IE 8 across XSS as a means of protection against attacks</p>
<p>From the article: </p>
<p>&quot;NoScript is in disagreement with the add-on in IE8.<br />
It analyses answers server and not requests for users, which could be the attackers of manipulation of answers server and injection certain codes for its implementation, Giorgio Maone says.</p>
<p>&quot;And who did not disclose the details of the matter is that the whole matter is based on an error in the basic design, which should be reconsidered in the design, Maone adds.&quot;</p>
<p>Pretty bad translation &#8212; I know people who could do better &#8212; but the bottom line comes out the same in any language. Looks like the whole world knows the story. :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tech Thursday – Python and YQL, new Google layout, Quake in Flash and LOLSQL &#124; Techno Portal</title>
		<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16306</link>
		<dc:creator>Tech Thursday – Python and YQL, new Google layout, Quake in Flash and LOLSQL &#124; Techno Portal</dc:creator>
		<pubDate>Thu, 26 Nov 2009 15:23:06 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16306</guid>
		<description>[...] Ironically a bug in Internet Explorer’s XSS filter allows to inject code into web sites. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Ironically a bug in Internet Explorer’s XSS filter allows to inject code into web sites. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: وسيلة الحماية من هجمات XSS على Internet Explorer 8 غير آمنة &#124; المجلة التقنية</title>
		<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16302</link>
		<dc:creator>وسيلة الحماية من هجمات XSS على Internet Explorer 8 غير آمنة &#124; المجلة التقنية</dc:creator>
		<pubDate>Thu, 26 Nov 2009 09:38:30 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16302</guid>
		<description>[...] http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/   Share and Enjoy: [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] <a href="http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/" rel="nofollow">http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/</a>   Share and Enjoy: [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr. Foo</title>
		<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16291</link>
		<dc:creator>Mr. Foo</dc:creator>
		<pubDate>Wed, 25 Nov 2009 11:24:31 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16291</guid>
		<description>&lt;strong&gt;XSS-Schutz des IE8 exploitbar&lt;/strong&gt;

Der XSS-Schutz des IE8 bröckelt.Der neueingeführte Cross-Site-Scripting Schutz des Internet Explorer 8 lässt sich anscheinend aushebeln.
Gorgio (der Entwickler von NoScript) berichtet in einem Blogeintrag darüber.
Konkret liegt das Problem in der...</description>
		<content:encoded><![CDATA[<p><strong>XSS-Schutz des IE8 exploitbar</strong></p>
<p>Der XSS-Schutz des IE8 bröckelt.Der neueingeführte Cross-Site-Scripting Schutz des Internet Explorer 8 lässt sich anscheinend aushebeln.<br />
Gorgio (der Entwickler von NoScript) berichtet in einem Blogeintrag darüber.<br />
Konkret liegt das Problem in der&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16289</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Wed, 25 Nov 2009 01:52:44 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16289</guid>
		<description>&#62; Nope, a POST unsafe reload doesn’t break anything because the filtered request had been turned in a data-less GET and therefore did not modify webapp status.

I was refering to one time.. where the POST was stripped but the GET args were left, so it trigers an error (with the GET args) since there's no POST data.. then if you do unsafe reload, it trigers an error since the nonce sent via GET was used before.

anyway, I only found that specific case on some openid service I was pentesting.. (against logic flaw errors, nothing to do with xss).. but well..

Greetz!</description>
		<content:encoded><![CDATA[<p>&gt; Nope, a POST unsafe reload doesn’t break anything because the filtered request had been turned in a data-less GET and therefore did not modify webapp status.</p>
<p>I was refering to one time.. where the POST was stripped but the GET args were left, so it trigers an error (with the GET args) since there&#8217;s no POST data.. then if you do unsafe reload, it trigers an error since the nonce sent via GET was used before.</p>
<p>anyway, I only found that specific case on some openid service I was pentesting.. (against logic flaw errors, nothing to do with xss).. but well..</p>
<p>Greetz!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16276</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 24 Nov 2009 11:09:51 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16276</guid>
		<description>@&lt;a href="http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16270" rel="nofollow"&gt;sirdarckcat&lt;/a&gt;:

Thanks for your comment.

Yes, I was referring to "unsafe reload".
&lt;blockquote&gt;
break things (POST unsafe reloads for instance)
&lt;/blockquote&gt;
Nope, a POST unsafe reload doesn't break anything because the filtered request had been turned in a data-less GET and therefore did not modify webapp status.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16270" rel="nofollow">sirdarckcat</a>:</p>
<p>Thanks for your comment.</p>
<p>Yes, I was referring to &#8220;unsafe reload&#8221;.</p>
<blockquote><p>
break things (POST unsafe reloads for instance)
</p></blockquote>
<p>Nope, a POST unsafe reload doesn&#8217;t break anything because the filtered request had been turned in a data-less GET and therefore did not modify webapp status.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16270</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Tue, 24 Nov 2009 08:07:08 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16270</guid>
		<description>#9 @giorgio
thankz! thats a great ppt!!

regarding slide 16: user can disable the filter..

Anyway, mmm maybe you mean &#34;unsafe reload&#34; so then you are right.. that's not possible..

I think webkit's approach compared to IE's is better (regarding compatibility) but IE is safer (actually, is the one with less bypasses so far.. evendo they did created security issues with the response rewriting approach..).. but NoScript request modification is known to either:
1.- break things (POST unsafe reloads for instance)
2.- hard to spot bugs (I wasnt used to check the error console before)

I would recommend you to allow the server to disable NoScript's filter.. anyway, I dont have any good idea on how to do it.. =/

Said that.. great ppt again!!  :)

Greetings!!</description>
		<content:encoded><![CDATA[<p>#9 @giorgio<br />
thankz! thats a great ppt!!</p>
<p>regarding slide 16: user can disable the filter..</p>
<p>Anyway, mmm maybe you mean &quot;unsafe reload&quot; so then you are right.. that&#8217;s not possible..</p>
<p>I think webkit&#8217;s approach compared to IE&#8217;s is better (regarding compatibility) but IE is safer (actually, is the one with less bypasses so far.. evendo they did created security issues with the response rewriting approach..).. but NoScript request modification is known to either:<br />
1.- break things (POST unsafe reloads for instance)<br />
2.- hard to spot bugs (I wasnt used to check the error console before)</p>
<p>I would recommend you to allow the server to disable NoScript&#8217;s filter.. anyway, I dont have any good idea on how to do it.. =/</p>
<p>Said that.. great ppt again!!  :)</p>
<p>Greetings!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16245</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Mon, 23 Nov 2009 17:16:30 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16245</guid>
		<description>@&lt;a href="http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16235" rel="nofollow"&gt;sirdarckcat&lt;/a&gt;:
http://maone.net/downloads/OWASP-Italy_Day_IV_Maone.pdf</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16235" rel="nofollow">sirdarckcat</a>:<br />
<a href="http://maone.net/downloads/OWASP-Italy_Day_IV_Maone.pdf" rel="nofollow">http://maone.net/downloads/OWASP-Italy_Day_IV_Maone.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16235</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Mon, 23 Nov 2009 11:30:50 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/#comment-16235</guid>
		<description>Hey could you upload your ppt? the owasp site fails..</description>
		<content:encoded><![CDATA[<p>Hey could you upload your ppt? the owasp site fails..</p>
]]></content:encoded>
	</item>
</channel>
</rss>
