<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Firefox 3.6&#8217;s &#8220;0-Day&#8221; and You</title>
	<link>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 08 Feb 2012 11:49:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: hackademix.net » Why NoScript Blocks Web Fonts</title>
		<link>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22774</link>
		<dc:creator>hackademix.net » Why NoScript Blocks Web Fonts</dc:creator>
		<pubDate>Wed, 24 Mar 2010 11:05:22 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22774</guid>
		<description>[...] Firefox 3.6’s “0-Day” and You      24 03 2010 [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Firefox 3.6’s “0-Day” and You      24 03 2010 [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Twitter Trackbacks for hackademix.net » Firefox 3.6's &#34;0-Day&#34; and You [hackademix.net] on Topsy.com</title>
		<link>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22773</link>
		<dc:creator>Twitter Trackbacks for hackademix.net » Firefox 3.6's &#34;0-Day&#34; and You [hackademix.net] on Topsy.com</dc:creator>
		<pubDate>Wed, 24 Mar 2010 10:59:28 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22773</guid>
		<description>[...] hackademix.net » Firefox 3.6's &#34;0-Day&#34; and You  hackademix.net/2010/03/22/firefox-36s-0-day-and-you – view page – cached  Bürger-CERT (”German’s official cyber-security response team”) is warning users against using Firefox until version 3.6.2 (scheduled on March the 30^th) is out, on the assumption that Secunia SA38608 needs to be considered a 0-day threat, but: 1. There’s no evidence of this vulnerability being exploited in the wild, even though paying customers of the VulnDisco security product have been... Read moreBürger-CERT (”German’s official cyber-security response team”) is warning users against using Firefox until version 3.6.2 (scheduled on March the 30^th) is out, on the assumption that Secunia SA38608 needs to be considered a 0-day threat, but: 1. There’s no evidence of this vulnerability being exploited in the wild, even though paying customers of the VulnDisco security product have been given access to a working exploit since February the 1^st. View page            Filter tweets [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] hackademix.net » Firefox 3.6&#8217;s &quot;0-Day&quot; and You  hackademix.net/2010/03/22/firefox-36s-0-day-and-you – view page – cached  Bürger-CERT (”German’s official cyber-security response team”) is warning users against using Firefox until version 3.6.2 (scheduled on March the 30^th) is out, on the assumption that Secunia SA38608 needs to be considered a 0-day threat, but: 1. There’s no evidence of this vulnerability being exploited in the wild, even though paying customers of the VulnDisco security product have been&#8230; Read moreBürger-CERT (”German’s official cyber-security response team”) is warning users against using Firefox until version 3.6.2 (scheduled on March the 30^th) is out, on the assumption that Secunia SA38608 needs to be considered a 0-day threat, but: 1. There’s no evidence of this vulnerability being exploited in the wild, even though paying customers of the VulnDisco security product have been given access to a working exploit since February the 1^st. View page            Filter tweets [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22771</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 23 Mar 2010 16:40:56 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22771</guid>
		<description>@&lt;a href="http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22770" rel="nofollow"&gt;BC&lt;/a&gt;:
Exactly this kind of scenario. 
Current font parsers are rather old, and have been implemented without the "fonts as a possible remote attack vector" mindset.
Now that any web page can feed them, fonts are much more dangerous than simple images (which still, from time to time, suffer from codec bugs) and at least as dangerous as generic plugin content.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22770" rel="nofollow">BC</a>:<br />
Exactly this kind of scenario.<br />
Current font parsers are rather old, and have been implemented without the &#8220;fonts as a possible remote attack vector&#8221; mindset.<br />
Now that any web page can feed them, fonts are much more dangerous than simple images (which still, from time to time, suffer from codec bugs) and at least as dangerous as generic plugin content.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BC</title>
		<link>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22770</link>
		<dc:creator>BC</dc:creator>
		<pubDate>Tue, 23 Mar 2010 14:35:26 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22770</guid>
		<description>What was the original reasoning for blocking embedded fonts?</description>
		<content:encoded><![CDATA[<p>What was the original reasoning for blocking embedded fonts?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How do I manually rid my computer of malware and spyware that hijacks my internet browser? &#124; Malware Bouncer &#124; Malware Bites</title>
		<link>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22769</link>
		<dc:creator>How do I manually rid my computer of malware and spyware that hijacks my internet browser? &#124; Malware Bouncer &#124; Malware Bites</dc:creator>
		<pubDate>Tue, 23 Mar 2010 14:31:07 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22769</guid>
		<description>[...] hackademix.net Â» Firefox 3.6’s “0-Day” and You [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] hackademix.net Â» Firefox 3.6’s “0-Day” and You [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22764</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 23 Mar 2010 08:36:39 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22764</guid>
		<description>@&lt;a href="http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22763" rel="nofollow"&gt;Faust&lt;/a&gt;:
No, it is not Java-related, but don't forget that "embedding" blocked by NoScript are not limited to Java :)

Anyway, having analyzed the bug in question &lt;em&gt;before&lt;/em&gt; making it, I can confirm that my statement about NoScript protection is correct.

&lt;strong&gt;Edit 2010-03-23&lt;/strong&gt;
Now that details are not embargoed anymore, I can tell you that exploitation required the browser to download a specially crafted web font. The relevant (default) NoScript setting against this is &lt;em&gt;NoScript Options&#124;Embeddings&#124;Forbid @font-face&lt;/em&gt;.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22763" rel="nofollow">Faust</a>:<br />
No, it is not Java-related, but don&#8217;t forget that &#8220;embedding&#8221; blocked by NoScript are not limited to Java :)</p>
<p>Anyway, having analyzed the bug in question <em>before</em> making it, I can confirm that my statement about NoScript protection is correct.</p>
<p><strong>Edit 2010-03-23</strong><br />
Now that details are not embargoed anymore, I can tell you that exploitation required the browser to download a specially crafted web font. The relevant (default) NoScript setting against this is <em>NoScript Options|Embeddings|Forbid @font-face</em>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Faust</title>
		<link>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22763</link>
		<dc:creator>Faust</dc:creator>
		<pubDate>Tue, 23 Mar 2010 05:50:10 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22763</guid>
		<description>So I assume from #3 that this exploit involves java?  Haven't yet seen that confirmed.</description>
		<content:encoded><![CDATA[<p>So I assume from #3 that this exploit involves java?  Haven&#8217;t yet seen that confirmed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Social networkers scared of scam as identity theft hits Russian sites &#124; SocialDaily.info</title>
		<link>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22762</link>
		<dc:creator>Social networkers scared of scam as identity theft hits Russian sites &#124; SocialDaily.info</dc:creator>
		<pubDate>Mon, 22 Mar 2010 21:08:17 +0000</pubDate>
		<guid>http://hackademix.net/2010/03/22/firefox-36s-0-day-and-you/#comment-22762</guid>
		<description>[...] hackademix.net » Firefox 3.6's &#34;0-Day&#34; and You [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] hackademix.net » Firefox 3.6&#8217;s &quot;0-Day&quot; and You [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

