<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Firefox fixes Internet Explorer flaw</title>
	<atom:link href="http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/</link>
	<description>Me, myself and I</description>
	<pubDate>Mon, 08 Sep 2008 18:12:58 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: B?ad w Firefox, nieprawid?owe filtrowanie wyra?e? w linkach. &#124; tPython</title>
		<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-1121</link>
		<dc:creator>B?ad w Firefox, nieprawid?owe filtrowanie wyra?e? w linkach. &#124; tPython</dc:creator>
		<pubDate>Thu, 26 Jul 2007 13:56:45 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-1121</guid>
		<description>[...] Foundation poprawi?a b??d wraz z wersj? 2.0.0.5, problem po stronie IE zosta? po raz kolejny zignorowany (wprawdzie w tym przypadku jest to cz??ciowo zrozumia?e, gdy? przecie? istnieje mo?liwo??, [...]</description>
		<content:encoded><![CDATA[<p>[...] Foundation poprawi?a b??d wraz z wersj? 2.0.0.5, problem po stronie IE zosta? po raz kolejny zignorowany (wprawdzie w tym przypadku jest to cz??ciowo zrozumia?e, gdy? przecie? istnieje mo?liwo??, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Attack of the URL Vulnerabilities &#124; GNUCITIZEN</title>
		<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-1076</link>
		<dc:creator>Attack of the URL Vulnerabilities &#124; GNUCITIZEN</dc:creator>
		<pubDate>Wed, 25 Jul 2007 09:53:07 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-1076</guid>
		<description>[...] related to the infamous bugs that has been recently discussed on multiple blogs including GC (us), Thor Larholm&#8217;s blog, Mozilla&#8217;s Security Blog, the 0&#215;000000 hack zine and Billy (BK) Rios&#8216; [...]</description>
		<content:encoded><![CDATA[<p>[...] related to the infamous bugs that has been recently discussed on multiple blogs including GC (us), Thor Larholm&#8217;s blog, Mozilla&#8217;s Security Blog, the 0&#215;000000 hack zine and Billy (BK) Rios&#8216; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larholm.com - Me, myself and I &#187; SeaMonkey suite affected by URL vulnerability</title>
		<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-1034</link>
		<dc:creator>Larholm.com - Me, myself and I &#187; SeaMonkey suite affected by URL vulnerability</dc:creator>
		<pubDate>Mon, 23 Jul 2007 15:12:34 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-1034</guid>
		<description>[...] Firefox fixes Internet Explorer flaw  [...]</description>
		<content:encoded><![CDATA[<p>[...] Firefox fixes Internet Explorer flaw  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thor Larholm</title>
		<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-982</link>
		<dc:creator>Thor Larholm</dc:creator>
		<pubDate>Fri, 20 Jul 2007 18:34:25 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-982</guid>
		<description>Biju, SeaMonkey should be affected as well as it registers a similar URL protocol handler, called SeaMonkeyURL. The definition can be found at &lt;a href="http://lxr.mozilla.org/seamonkey/source/suite/installer/windows/nsis/shared.nsh#157" rel="nofollow"&gt;http://lxr.mozilla.org/seamonkey/source/suite/installer/windows/nsis/shared.nsh#157&lt;/a&gt;

The fix in Firefox 2.0.0.5 prevents any kind of additional arguments from being parsed if Firefox is launched as a URL protocol handler. Other applications can still be called with arbitrary arguments.

Regards
Thor Larholm</description>
		<content:encoded><![CDATA[<p>Biju, SeaMonkey should be affected as well as it registers a similar URL protocol handler, called SeaMonkeyURL. The definition can be found at <a href="http://lxr.mozilla.org/seamonkey/source/suite/installer/windows/nsis/shared.nsh#157" rel="nofollow">http://lxr.mozilla.org/seamonkey/source/suite/installer/windows/nsis/shared.nsh#157</a></p>
<p>The fix in Firefox 2.0.0.5 prevents any kind of additional arguments from being parsed if Firefox is launched as a URL protocol handler. Other applications can still be called with arbitrary arguments.</p>
<p>Regards<br />
Thor Larholm</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Symantec gives its ThreatCon a makeover &#8212; Security Bytes</title>
		<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-973</link>
		<dc:creator>Symantec gives its ThreatCon a makeover &#8212; Security Bytes</dc:creator>
		<pubDate>Fri, 20 Jul 2007 09:33:59 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-973</guid>
		<description>[...] Thor Larholm, one of the researchers who brought this problem to light, says in his Larhom.com blog that the Firefox update isn&#8217;t the end of the [...]</description>
		<content:encoded><![CDATA[<p>[...] Thor Larholm, one of the researchers who brought this problem to light, says in his Larhom.com blog that the Firefox update isn&#8217;t the end of the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Biju</title>
		<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-966</link>
		<dc:creator>Biju</dc:creator>
		<pubDate>Fri, 20 Jul 2007 04:19:44 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-966</guid>
		<description>Thor,

1. I dont see SeaMonkey and other moz products mentioned, whether they are also affected?

2. your example show attack vector with javascript:, whether current firefox fix also stops chrome://, file://, jar://, resource:// being called?

3. what about target apps that registers scp:// ftp:// ssh:// protocals, ie apps like PuTTY, WinSCP, FileZilla, as well as P2P apps. any report them being tested for similar possible attack.

Thanks...</description>
		<content:encoded><![CDATA[<p>Thor,</p>
<p>1. I dont see SeaMonkey and other moz products mentioned, whether they are also affected?</p>
<p>2. your example show attack vector with javascript:, whether current firefox fix also stops chrome://, file://, jar://, resource:// being called?</p>
<p>3. what about target apps that registers scp:// <a href="ftp://" rel="nofollow">ftp://</a> ssh:// protocals, ie apps like PuTTY, WinSCP, FileZilla, as well as P2P apps. any report them being tested for similar possible attack.</p>
<p>Thanks&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harry Johnston</title>
		<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-962</link>
		<dc:creator>Harry Johnston</dc:creator>
		<pubDate>Fri, 20 Jul 2007 00:14:17 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-962</guid>
		<description>I can't claim to be an expert on ActiveX; I was basing my (apparently erroneous) assumption on the number of vulnerability notices I've read over the years that seemed to boil down to an ActiveX component being inappropriately exposed to web sites.  (For one thing, there was hardly a cumulative IE update that didn't set the kill bit for at least one control!)

I'll accept that my statement was technically incorrect; however, it still seems that it is too easy (in practice) for software to expose an ActiveX control to the web without meaning to?</description>
		<content:encoded><![CDATA[<p>I can&#8217;t claim to be an expert on ActiveX; I was basing my (apparently erroneous) assumption on the number of vulnerability notices I&#8217;ve read over the years that seemed to boil down to an ActiveX component being inappropriately exposed to web sites.  (For one thing, there was hardly a cumulative IE update that didn&#8217;t set the kill bit for at least one control!)</p>
<p>I&#8217;ll accept that my statement was technically incorrect; however, it still seems that it is too easy (in practice) for software to expose an ActiveX control to the web without meaning to?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: foxiewire.com</title>
		<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-955</link>
		<dc:creator>foxiewire.com</dc:creator>
		<pubDate>Thu, 19 Jul 2007 19:55:47 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-955</guid>
		<description>&lt;strong&gt;Larholm.com - Me, myself and I			 » Firefox fixes Internet Explorer flaw...&lt;/strong&gt;

Mozilla has just released Firefox 2.0.0.5 which purportedly fixes one of the attack vectors of the Internet Explorer input validation flaw that I previously detailed. I will go on the record as stating that this does not actually fix the flaw in Intern...</description>
		<content:encoded><![CDATA[<p><strong>Larholm.com - Me, myself and I			 » Firefox fixes Internet Explorer flaw&#8230;</strong></p>
<p>Mozilla has just released Firefox 2.0.0.5 which purportedly fixes one of the attack vectors of the Internet Explorer input validation flaw that I previously detailed. I will go on the record as stating that this does not actually fix the flaw in Intern&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thor Larholm</title>
		<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-938</link>
		<dc:creator>Thor Larholm</dc:creator>
		<pubDate>Thu, 19 Jul 2007 10:05:57 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-938</guid>
		<description>Kimblim, I mean both :)

Regards
Thor Larholm</description>
		<content:encoded><![CDATA[<p>Kimblim, I mean both <img src='http://larholm.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Regards<br />
Thor Larholm</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kimblim</title>
		<link>http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-937</link>
		<dc:creator>kimblim</dc:creator>
		<pubDate>Thu, 19 Jul 2007 09:40:41 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/18/firefox-fixes-internet-explorer-flaw/#comment-937</guid>
		<description>Thor,
When you say Internet Explorer, do you mean IE6 or IE7? Or do you mean both?</description>
		<content:encoded><![CDATA[<p>Thor,<br />
When you say Internet Explorer, do you mean IE6 or IE7? Or do you mean both?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
