<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: An IE Browser is EVEN exploitible on DSL Repor in </title>
<link>http://www.dslreports.com/forum/r7506766</link>
<description></description>
<language>en</language>
<pubDate>Tue, 24 Nov 2009 14:17:33 EDT</pubDate>
<lastBuildDate>Tue, 24 Nov 2009 14:17:33 EDT</lastBuildDate>

<item>
<title>Re: An IE Browser is EVEN exploitible on DSL Repor</title>
<link>http://www.dslreports.com/forum/remark,7507104</link>
<description><![CDATA[<A HREF="/useremail/u/732377"><b>Marilla</b></A> : I'm VERY busy this weekend, and as I noted in the thread, I've not used Javascript for much other than form validation and simply redirection of the browser... but when I get time, I'll work on a 'proof of concept' post in the forum you linked, NIL.<br><br>And btw, thank you for taking time out for this.. I, too, am very interested in the outcome since I run my own custom forum system myself; I thought I had taken care of a lot of malicious possible uses before... but we'll see<br><br>Perhaps someone will get to a 'proof of concept' before I do.. we'll just see.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7507104</guid>
<pubDate>Sat, 26 Jul 2003 15:25:34 EDT</pubDate>
</item>

<item>
<title>Re: An IE Browser is EVEN exploitible on DSL Repor</title>
<link>http://www.dslreports.com/forum/remark,7506784</link>
<description><![CDATA[<A HREF="/useremail/u/251107"><b>nil</b></A> : Okay, sure, why not.. There's one way to about it.. See my new post in the other thread. <br><small>--<br>Life is too short to be <A HREF="http://www.unix-girl.com/blog/">boring</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7506784</guid>
<pubDate>Sat, 26 Jul 2003 14:40:06 EDT</pubDate>
</item>

<item>
<title>Re: An IE Browser is EVEN exploitible on DSL Repor</title>
<link>http://www.dslreports.com/forum/remark,7506766</link>
<description><![CDATA[<A HREF="/useremail/u/820934"><b>Sarick</b></A> : I would love to see both parties that debute over this some more. :)<br><br>One person says it's exploitible the other says it's not.<br><br>My problem is I can't argue with anyone I don't program Java Script. <br><br>A couple of people tend to think it's still open for debate. :)<br><br>I do miss your insite. After all it's my understanding that your head of this sites web design or have a lot of say on it's design and or performance. ;)<br><br>Like I said before I try to lock down my system as much as possible. Having an exploit install something is rare but I don't want to deal with to much paranoid issues that could cause brain damage. :)<br><br>Most of the exploits IE has are because it's so inter twind with the OS. I bet there are still many hacks not found in the wild in IE.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7506766</guid>
<pubDate>Sat, 26 Jul 2003 14:36:38 EDT</pubDate>
</item>

<item>
<title>Re: An IE Browser is EVEN exploitible on DSL Repor</title>
<link>http://www.dslreports.com/forum/remark,7506703</link>
<description><![CDATA[<A HREF="/useremail/u/251107"><b>nil</b></A> : JavaScript is client side.. hence all the various little tricks you can do with it only work for the person viewing the site.. so yes.. someone could insert an iframe that will display contents of /prof.. but guess whose you will view? Your own.. and you can't view someone elses.. <br><small>--<br>Life is too short to be <A HREF="http://www.unix-girl.com/blog/">boring</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7506703</guid>
<pubDate>Sat, 26 Jul 2003 14:25:45 EDT</pubDate>
</item>

<item>
<title>Re: An IE Browser is EVEN exploitible on DSL Repor</title>
<link>http://www.dslreports.com/forum/remark,7506680</link>
<description><![CDATA[<A HREF="/useremail/u/820934"><b>Sarick</b></A> :  <BLOCKQUOTE><SMALL>said by  nil <A HREF="/useremail/u/251107"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>Well.. it really doesn't.. <br><br>As I explained in that thread.. dslr security is based on more than just the cookie so ability to execute arbitrary javascript isn't exactly a huge security hole. <br><br> <HR></BLOCKQUOTE><br>No recheck the topic. A lot of new stuff got added. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7506680</guid>
<pubDate>Sat, 26 Jul 2003 14:22:20 EDT</pubDate>
</item>

<item>
<title>Re: An IE Browser is EVEN exploitible on DSL Repor</title>
<link>http://www.dslreports.com/forum/remark,7506380</link>
<description><![CDATA[<A HREF="/useremail/u/251107"><b>nil</b></A> : Well.. it really doesn't.. <br><br>As I explained in that thread.. dslr security is based on more than just the cookie so ability to execute arbitrary javascript isn't exactly a huge security hole. <br><br><small>--<br>Life is too short to be <A HREF="http://www.unix-girl.com/blog/">boring</a></small><br><i>[text was edited by author 2003-07-26 13:39:47]</i>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7506380</guid>
<pubDate>Sat, 26 Jul 2003 13:38:50 EDT</pubDate>
</item>

<item>
<title>An IE Browser is EVEN exploitible on DSL Reports</title>
<link>http://www.dslreports.com/forum/remark,7506340</link>
<description><![CDATA[<A HREF="/useremail/u/820934"><b>Sarick</b></A> : I Ask about DSLreports and the possibility of a security risk from clicking on URL links. <br><br>&raquo;<A HREF="/forum/remark,7429671">DSLreports Clicking a link in forums?</A><br><br>Turns out a lot of people didn't even know it existed..<br><i>[text was edited by author 2003-07-26 13:37:00]</i>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,7506340</guid>
<pubDate>Sat, 26 Jul 2003 13:34:29 EDT</pubDate>
</item>

</channel>
</rss>
