<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: vicious vicious browser exploit</title>
	<atom:link href="http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/</link>
	<description>stargazer, muddler, muffle-jaw, cockatouch, spoonhead, hookear, gudgeon, grubby, blob, bull-rout, blue garnet, miller's thumb</description>
	<lastBuildDate>Tue, 27 Jul 2010 15:42:14 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Tungsten</title>
		<link>http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/comment-page-1/#comment-43</link>
		<dc:creator>Tungsten</dc:creator>
		<pubDate>Mon, 07 Feb 2005 23:11:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/#comment-43</guid>
		<description>Thank you!</description>
		<content:encoded><![CDATA[<p>Thank you!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ted</title>
		<link>http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/comment-page-1/#comment-42</link>
		<dc:creator>Ted</dc:creator>
		<pubDate>Mon, 07 Feb 2005 22:11:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/#comment-42</guid>
		<description>Ouch.  Yeah, I&#039;ll be disabling IDN when I get home.</description>
		<content:encoded><![CDATA[<p>Ouch.  Yeah, I&#8217;ll be disabling IDN when I get home.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cam</title>
		<link>http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/comment-page-1/#comment-41</link>
		<dc:creator>Cam</dc:creator>
		<pubDate>Mon, 07 Feb 2005 19:42:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/#comment-41</guid>
		<description>Yep. You&#039;ve probably seen &lt;a href=&quot;http://www.elsewhere.org/journal/archives/2005/02/07/wow-just-wow/&quot;&gt;Josh&#039;s explanation&lt;/a&gt; already, but if not, imagine that you&#039;re a bad guy and you want to take advantage of this. What could you do?

It would be simple and effective to send out phishing email that would appear to direct people to a legitimate site but would really direct them to your own con-artist website.

Or let&#039;s imagine that you manage to hack into a website, say, the Red Cross site. Instead of announcing &quot;this site is pwnz0red!&quot; you make a visually indetectible change that sends visitors to your con-artist website to make their donations. Depending on how clever you are and how careful the site administrators are, you could collect quite a bundle.</description>
		<content:encoded><![CDATA[<p>Yep. You&#8217;ve probably seen <a href="http://www.elsewhere.org/journal/archives/2005/02/07/wow-just-wow/">Josh&#8217;s explanation</a> already, but if not, imagine that you&#8217;re a bad guy and you want to take advantage of this. What could you do?</p>
<p>It would be simple and effective to send out phishing email that would appear to direct people to a legitimate site but would really direct them to your own con-artist website.</p>
<p>Or let&#8217;s imagine that you manage to hack into a website, say, the Red Cross site. Instead of announcing &#8220;this site is pwnz0red!&#8221; you make a visually indetectible change that sends visitors to your con-artist website to make their donations. Depending on how clever you are and how careful the site administrators are, you could collect quite a bundle.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ted</title>
		<link>http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/comment-page-1/#comment-39</link>
		<dc:creator>Ted</dc:creator>
		<pubDate>Mon, 07 Feb 2005 18:34:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/#comment-39</guid>
		<description>Is this something you need to worry about if you don&#039;t have your own website?</description>
		<content:encoded><![CDATA[<p>Is this something you need to worry about if you don&#8217;t have your own website?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: StopIE</title>
		<link>http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/comment-page-1/#comment-38</link>
		<dc:creator>StopIE</dc:creator>
		<pubDate>Mon, 07 Feb 2005 17:05:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/#comment-38</guid>
		<description>Actually Firefox is still far more secure.

The only reason that this vulnerability doesn&#039;t affect IE is that IE doesn&#039;t follow the IDN standard at all.

It can be turned off extremely easily in Firefox:
1) type about:config in the address bar
2) disable &quot;network.enableIDN&quot;</description>
		<content:encoded><![CDATA[<p>Actually Firefox is still far more secure.</p>
<p>The only reason that this vulnerability doesn&#8217;t affect IE is that IE doesn&#8217;t follow the IDN standard at all.</p>
<p>It can be turned off extremely easily in Firefox:<br />
1) type about:config in the address bar<br />
2) disable &#8220;network.enableIDN&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rechercher</title>
		<link>http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/comment-page-1/#comment-37</link>
		<dc:creator>Rechercher</dc:creator>
		<pubDate>Mon, 07 Feb 2005 16:41:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.sculpin.com/journal/2005/02/07/vicious-vicious-browser-exploit/#comment-37</guid>
		<description>So much for Firefox being more secure than IE.</description>
		<content:encoded><![CDATA[<p>So much for Firefox being more secure than IE.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
