<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: X-Content-Type-Options, NoScript and Browserscope</title>
	<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 16 May 2012 22:16:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24325</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Mon, 03 Jan 2011 10:12:24 +0000</pubDate>
		<guid>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24325</guid>
		<description>@&lt;a href="http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24324" rel="nofollow"&gt;James&lt;/a&gt;:
Test #17 is bound to fail on Fx 3.6.x in default configuration (you could turn off visited link feedback from about:config, though), while Firefox 4 has a clever and permanent fix by default (AFAIK is the only browser implementing it).</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24324" rel="nofollow">James</a>:<br />
Test #17 is bound to fail on Fx 3.6.x in default configuration (you could turn off visited link feedback from about:config, though), while Firefox 4 has a clever and permanent fix by default (AFAIK is the only browser implementing it).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24324</link>
		<dc:creator>James</dc:creator>
		<pubDate>Mon, 03 Jan 2011 08:18:40 +0000</pubDate>
		<guid>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24324</guid>
		<description>I also failed test #17 - block visited link sniffing. I notice above this has already been reported, but I'm happy to mail you my Export Settings dump if you'd like.</description>
		<content:encoded><![CDATA[<p>I also failed test #17 - block visited link sniffing. I notice above this has already been reported, but I&#8217;m happy to mail you my Export Settings dump if you&#8217;d like.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24284</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Mon, 27 Dec 2010 14:25:24 +0000</pubDate>
		<guid>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24284</guid>
		<description>@&lt;a href="http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24283" rel="nofollow"&gt;jason&lt;/a&gt;:
Could you please reinstall NoScript just once and use the "Report" button on the ClearClick dialog when the problem happens, then mail me one or more report IDs for me to analyze?
Thank you.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24283" rel="nofollow">jason</a>:<br />
Could you please reinstall NoScript just once and use the &#8220;Report&#8221; button on the ClearClick dialog when the problem happens, then mail me one or more report IDs for me to analyze?<br />
Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jason</title>
		<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24283</link>
		<dc:creator>jason</dc:creator>
		<pubDate>Mon, 27 Dec 2010 12:44:13 +0000</pubDate>
		<guid>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24283</guid>
		<description>noscript USED to be a good program. but now it annoys the shit out of me when im on facebook. it will NOT allow 95% of the clicks on ANY of the games because of some &#34;hijack attempts&#34; notice. 
ive uninstalled it.
IF i hear that it works PROPERLY again, i MAY consider reinstalling it. Until such time, i WILL be recommending people find a different program to use.</description>
		<content:encoded><![CDATA[<p>noscript USED to be a good program. but now it annoys the shit out of me when im on facebook. it will NOT allow 95% of the clicks on ANY of the games because of some &quot;hijack attempts&quot; notice.<br />
ive uninstalled it.<br />
IF i hear that it works PROPERLY again, i MAY consider reinstalling it. Until such time, i WILL be recommending people find a different program to use.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24167</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Fri, 12 Nov 2010 15:59:55 +0000</pubDate>
		<guid>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24167</guid>
		<description>@&lt;a href="http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24166" rel="nofollow"&gt;p0deje&lt;/a&gt;:
The original IE8 implementation does not make sense, in fact, because Firefox doesn't sniff top-level documents.

However the stricter IE9/NoScript implementation, which restricts also script execution to correctly typed script files only, is actually useful to prevent file hosting services and public CMS platforms from being to deliver script-based attacks.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24166" rel="nofollow">p0deje</a>:<br />
The original IE8 implementation does not make sense, in fact, because Firefox doesn&#8217;t sniff top-level documents.</p>
<p>However the stricter IE9/NoScript implementation, which restricts also script execution to correctly typed script files only, is actually useful to prevent file hosting services and public CMS platforms from being to deliver script-based attacks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: p0deje</title>
		<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24166</link>
		<dc:creator>p0deje</dc:creator>
		<pubDate>Fri, 12 Nov 2010 15:47:54 +0000</pubDate>
		<guid>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24166</guid>
		<description>I don't understand what's the deal of X-Content-Type-Options header for Firefox. AFAIK the only exploitation way, which it mitigates is IE MIME-sniffer bug, but there isn't any like it in Firefox.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t understand what&#8217;s the deal of X-Content-Type-Options header for Firefox. AFAIK the only exploitation way, which it mitigates is IE MIME-sniffer bug, but there isn&#8217;t any like it in Firefox.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24128</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sat, 30 Oct 2010 19:22:31 +0000</pubDate>
		<guid>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24128</guid>
		<description>@&lt;a href="http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24127" rel="nofollow"&gt;Thomas Ludwig&lt;/a&gt;:
Origin could, but AFAIK is the one which is more likely to be implemented soon as a Firefox built-in.
Sandbox is much more problematic, because it's technically prohibitive for an extension and, on the other hand, there may be resistance to introduce it in Firefox since it overlaps to some extent with CSP.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24127" rel="nofollow">Thomas Ludwig</a>:<br />
Origin could, but AFAIK is the one which is more likely to be implemented soon as a Firefox built-in.<br />
Sandbox is much more problematic, because it&#8217;s technically prohibitive for an extension and, on the other hand, there may be resistance to introduce it in Firefox since it overlaps to some extent with CSP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas Ludwig</title>
		<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24127</link>
		<dc:creator>Thomas Ludwig</dc:creator>
		<pubDate>Sat, 30 Oct 2010 18:04:20 +0000</pubDate>
		<guid>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24127</guid>
		<description>@Giorgio: Thanks - understood!
BTW: You mentioned &#34;HTTP Origin Header and the HTML 5 Sandbox Attribute, which are not implemented yet by Firefox nor by NoScript.&#34; Could both be implemented in Noscript, and if so are you planning it?</description>
		<content:encoded><![CDATA[<p>@Giorgio: Thanks - understood!<br />
BTW: You mentioned &quot;HTTP Origin Header and the HTML 5 Sandbox Attribute, which are not implemented yet by Firefox nor by NoScript.&quot; Could both be implemented in Noscript, and if so are you planning it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24126</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sat, 30 Oct 2010 17:55:41 +0000</pubDate>
		<guid>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24126</guid>
		<description>@&lt;a href="http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24125" rel="nofollow"&gt;Thomas Ludwig&lt;/a&gt;:
Maybe there's a misunderstanding, you do not &lt;em&gt;need&lt;/em&gt; to disable XSS protection in order to take the test (quite the contrary).

Actually, you're getting 13 and 14, but you should get 12 and 13 because XSS protection is turned off: there's a bug in the test awarding you 1 point more than due on Firefox, as I told in the article.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24125" rel="nofollow">Thomas Ludwig</a>:<br />
Maybe there&#8217;s a misunderstanding, you do not <em>need</em> to disable XSS protection in order to take the test (quite the contrary).</p>
<p>Actually, you&#8217;re getting 13 and 14, but you should get 12 and 13 because XSS protection is turned off: there&#8217;s a bug in the test awarding you 1 point more than due on Firefox, as I told in the article.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas Ludwig</title>
		<link>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24125</link>
		<dc:creator>Thomas Ludwig</dc:creator>
		<pubDate>Sat, 30 Oct 2010 17:48:07 +0000</pubDate>
		<guid>http://hackademix.net/2010/10/30/x-content-type-options-noscript-and-browserscope/#comment-24125</guid>
		<description>Just re-ran the test with FF 4.0b8pre. Result: 14/16

Failed tests: Sandbox attribute, Origin header.</description>
		<content:encoded><![CDATA[<p>Just re-ran the test with FF 4.0b8pre. Result: 14/16</p>
<p>Failed tests: Sandbox attribute, Origin header.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

