<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Mozilla Protocol Abuse</title>
	<atom:link href="http://larholm.com/2007/07/25/mozilla-protocol-abuse/feed/" rel="self" type="application/rss+xml" />
	<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/</link>
	<description>Me, myself and I</description>
	<pubDate>Tue, 07 Oct 2008 22:59:11 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Stickymaddness</title>
		<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1206</link>
		<dc:creator>Stickymaddness</dc:creator>
		<pubDate>Sat, 28 Jul 2007 14:59:27 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1206</guid>
		<description>Great stuff, hats off to Thor Larholm! :)</description>
		<content:encoded><![CDATA[<p>Great stuff, hats off to Thor Larholm! <img src='http://larholm.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: [SSD] Security &#38; Development Blog &#187; Insisto: grave riesgo amenaza a usuarios de Firefox en Windows XP</title>
		<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1169</link>
		<dc:creator>[SSD] Security &#38; Development Blog &#187; Insisto: grave riesgo amenaza a usuarios de Firefox en Windows XP</dc:creator>
		<pubDate>Fri, 27 Jul 2007 15:29:35 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1169</guid>
		<description>[...] Mozilla Protocol Abuse [Larholm.com]. [...]</description>
		<content:encoded><![CDATA[<p>[...] Mozilla Protocol Abuse [Larholm.com]. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thor Larholm</title>
		<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1128</link>
		<dc:creator>Thor Larholm</dc:creator>
		<pubDate>Thu, 26 Jul 2007 15:02:51 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1128</guid>
		<description>ortis, Mozilla was already notified about this vulnerability and Thunderbird 2.0.0.5 protects against these exploits.

Regards
Thor Larholm</description>
		<content:encoded><![CDATA[<p>ortis, Mozilla was already notified about this vulnerability and Thunderbird 2.0.0.5 protects against these exploits.</p>
<p>Regards<br />
Thor Larholm</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ortis</title>
		<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1127</link>
		<dc:creator>ortis</dc:creator>
		<pubDate>Thu, 26 Jul 2007 14:49:14 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1127</guid>
		<description>hi,

It's good to discover a vuln but it's better to signal the vendor first. This should be the way a real man does, guy.</description>
		<content:encoded><![CDATA[<p>hi,</p>
<p>It&#8217;s good to discover a vuln but it&#8217;s better to signal the vendor first. This should be the way a real man does, guy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pat</title>
		<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1117</link>
		<dc:creator>Pat</dc:creator>
		<pubDate>Thu, 26 Jul 2007 10:30:49 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1117</guid>
		<description>Well done Thor. You certainly are clever, and it is refreshing to see someone write about exploits without resorting to "zomg h4x"-style language.

10 points for visual presentation and being easy to read, plus another 10 points for interesting content.</description>
		<content:encoded><![CDATA[<p>Well done Thor. You certainly are clever, and it is refreshing to see someone write about exploits without resorting to &#8220;zomg h4x&#8221;-style language.</p>
<p>10 points for visual presentation and being easy to read, plus another 10 points for interesting content.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: halans</title>
		<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1109</link>
		<dc:creator>halans</dc:creator>
		<pubDate>Thu, 26 Jul 2007 03:32:20 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1109</guid>
		<description>Great stuff, Thor!
FYI, Democracy Player changed into Miro.</description>
		<content:encoded><![CDATA[<p>Great stuff, Thor!<br />
FYI, Democracy Player changed into Miro.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larholm.com - Me, myself and I &#187; Thunderbird 1.5 has not been patched with osint</title>
		<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1107</link>
		<dc:creator>Larholm.com - Me, myself and I &#187; Thunderbird 1.5 has not been patched with osint</dc:creator>
		<pubDate>Thu, 26 Jul 2007 01:28:31 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1107</guid>
		<description>[...] Mozilla Protocol Abuse  [...]</description>
		<content:encoded><![CDATA[<p>[...] Mozilla Protocol Abuse  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alun Jones</title>
		<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1101</link>
		<dc:creator>Alun Jones</dc:creator>
		<pubDate>Wed, 25 Jul 2007 23:03:12 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1101</guid>
		<description>Hmm... txtfile:c:\autoexec.bat - yeah, that's a good URL. Even better is cmdfile:c:\windows\system32\calc.exe - gives a really scary-looking dialog box, and then fails to run anything. Fun-ny. I'm going to forward that one to /all/ my friends.</description>
		<content:encoded><![CDATA[<p>Hmm&#8230; txtfile:c:\autoexec.bat - yeah, that&#8217;s a good URL. Even better is cmdfile:c:\windows\system32\calc.exe - gives a really scary-looking dialog box, and then fails to run anything. Fun-ny. I&#8217;m going to forward that one to /all/ my friends.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ascii</title>
		<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1100</link>
		<dc:creator>ascii</dc:creator>
		<pubDate>Wed, 25 Jul 2007 22:54:53 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1100</guid>
		<description>Hi larholm, really good writeup!

I just wrote a little howto to completely disable external protocols handlers and whitelist only few protocols that are handled internally by Firefox:

http://www.ush.it/2007/07/25/clientside-security-hardening-mozilla-firefox/</description>
		<content:encoded><![CDATA[<p>Hi larholm, really good writeup!</p>
<p>I just wrote a little howto to completely disable external protocols handlers and whitelist only few protocols that are handled internally by Firefox:</p>
<p><a href="http://www.ush.it/2007/07/25/clientside-security-hardening-mozilla-firefox/" rel="nofollow">http://www.ush.it/2007/07/25/clientside-security-hardening-mozilla-firefox/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan McFeters</title>
		<link>http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1089</link>
		<dc:creator>Nathan McFeters</dc:creator>
		<pubDate>Wed, 25 Jul 2007 18:55:48 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/07/25/mozilla-protocol-abuse/#comment-1089</guid>
		<description>I love it Thor, good stuff.  Digging into it now... I suspect other browsers, mail clients, news readers, etc. could be vulnerable to this.</description>
		<content:encoded><![CDATA[<p>I love it Thor, good stuff.  Digging into it now&#8230; I suspect other browsers, mail clients, news readers, etc. could be vulnerable to this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
