<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: More 0day in Firebug</title>
	<atom:link href="http://larholm.com/2007/04/06/more-0day-in-firebug/feed/" rel="self" type="application/rss+xml" />
	<link>http://larholm.com/2007/04/06/more-0day-in-firebug/</link>
	<description>Me, myself and I</description>
	<pubDate>Wed, 19 Nov 2008 11:55:50 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Scriptorama.nl &#187; Maand van de problemen met browsers</title>
		<link>http://larholm.com/2007/04/06/more-0day-in-firebug/#comment-37</link>
		<dc:creator>Scriptorama.nl &#187; Maand van de problemen met browsers</dc:creator>
		<pubDate>Thu, 31 May 2007 06:38:48 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=8#comment-37</guid>
		<description>[...] maar met Firebug kom je lokaal in elk geval iets teveel info tegen. Combineer dat met de problemen die Firebug heeft gehad (en mensen die mogelijk nog die oude versie draaien) en dan is het toch zaak dat dat snel opgelost [...]</description>
		<content:encoded><![CDATA[<p>[...] maar met Firebug kom je lokaal in elk geval iets teveel info tegen. Combineer dat met de problemen die Firebug heeft gehad (en mensen die mogelijk nog die oude versie draaien) en dan is het toch zaak dat dat snel opgelost [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LimCore</title>
		<link>http://larholm.com/2007/04/06/more-0day-in-firebug/#comment-36</link>
		<dc:creator>LimCore</dc:creator>
		<pubDate>Tue, 22 May 2007 12:30:04 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=8#comment-36</guid>
		<description>I wonder will there be things like friefox internal firewall and antiviruses.

Perhaps even ASL(access control list)/RBAC.

To audit chrome contexts and so on.</description>
		<content:encoded><![CDATA[<p>I wonder will there be things like friefox internal firewall and antiviruses.</p>
<p>Perhaps even ASL(access control list)/RBAC.</p>
<p>To audit chrome contexts and so on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: New Start</title>
		<link>http://larholm.com/2007/04/06/more-0day-in-firebug/#comment-32</link>
		<dc:creator>New Start</dc:creator>
		<pubDate>Mon, 30 Apr 2007 05:47:29 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=8#comment-32</guid>
		<description>&lt;strong&gt;Firebug Goes Evilï¼ˆfirebug1.0.3ä¹‹å‰çš„å®‰å…¨éšæ‚£ï¼‰...&lt;/strong&gt;

firebugå­˜åœ¨ä¸¥é‡å®‰å…¨éšæ‚£...</description>
		<content:encoded><![CDATA[<p><strong>Firebug Goes Evilï¼ˆfirebug1.0.3ä¹‹å‰çš„å®‰å…¨éšæ‚£ï¼‰&#8230;</strong></p>
<p>firebugå­˜åœ¨ä¸¥é‡å®‰å…¨éšæ‚£&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe Hewitt</title>
		<link>http://larholm.com/2007/04/06/more-0day-in-firebug/#comment-30</link>
		<dc:creator>Joe Hewitt</dc:creator>
		<pubDate>Fri, 06 Apr 2007 02:44:22 +0000</pubDate>
		<guid isPermaLink="false">http://test.larholm.com/?p=8#comment-30</guid>
		<description>I have fixed this issue and and released 1.04.

As you suggested, I now escape all text before inserting it into HTML, rather than leaving it up to the caller.  I've also added support for disabling file: urls.

I hope there aren't any more vulnerabilities to be found, but if there are, please give me a day to patch it before you publish.  I do appreciate you taking the time to make Firebug more secure, but it's better for everyone to have the patch surface before the exploit.

It is a good think that Firefox has an automatic update system, so every Firebug user should be secured within a few days.</description>
		<content:encoded><![CDATA[<p>I have fixed this issue and and released 1.04.</p>
<p>As you suggested, I now escape all text before inserting it into HTML, rather than leaving it up to the caller.  I&#8217;ve also added support for disabling file: urls.</p>
<p>I hope there aren&#8217;t any more vulnerabilities to be found, but if there are, please give me a day to patch it before you publish.  I do appreciate you taking the time to make Firebug more secure, but it&#8217;s better for everyone to have the patch surface before the exploit.</p>
<p>It is a good think that Firefox has an automatic update system, so every Firebug user should be secured within a few days.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
