<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Firefox chrome: URL Handling Directory Traversal.</title>
	<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/</link>
	<description>relevant ramblings of an ethical hacker</description>
	<pubDate>Fri, 04 Jul 2008 14:12:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.2</generator>
		<item>
		<title>By: bssairtools</title>
		<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-1543</link>
		<dc:creator>bssairtools</dc:creator>
		<pubDate>Mon, 23 Jun 2008 01:09:59 +0000</pubDate>
		<guid>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-1543</guid>
		<description>Wenling BSS air tools Co.,Ltd. was established in 1997, and located in Zhejiang Wenling which is a beautiful seashore city with convenient transportation.
The company is specialized in manufacturing air tools including air spray gun, air cleanning gun, air duster gun ,air hoses,tire inflating gun,building paint gun,glue gun,air tools parts etc. 
To insure good quality, we have lead modern production equipment and inspection instruments including DIE-CASTING machine, CNC finish machine and polisher machine.
Our product are sold well to local market and oversea market including Asia, USA, EU, AFRICA and so on due to the super quality and excellent service. 
Welcome to cooperate with us!</description>
		<content:encoded><![CDATA[<p>Wenling BSS air tools Co.,Ltd. was established in 1997, and located in Zhejiang Wenling which is a beautiful seashore city with convenient transportation.<br />
The company is specialized in manufacturing air tools including air spray gun, air cleanning gun, air duster gun ,air hoses,tire inflating gun,building paint gun,glue gun,air tools parts etc.<br />
To insure good quality, we have lead modern production equipment and inspection instruments including DIE-CASTING machine, CNC finish machine and polisher machine.<br />
Our product are sold well to local market and oversea market including Asia, USA, EU, AFRICA and so on due to the super quality and excellent service.<br />
Welcome to cooperate with us!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: delicious mark hubery</title>
		<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-1125</link>
		<dc:creator>delicious mark hubery</dc:creator>
		<pubDate>Thu, 17 Apr 2008 20:16:33 +0000</pubDate>
		<guid>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-1125</guid>
		<description>&lt;strong&gt;Blog Hopper...&lt;/strong&gt;

Hi There. I'm blog hopping....</description>
		<content:encoded><![CDATA[<p><strong>Blog Hopper&#8230;</strong></p>
<p>Hi There. I&#8217;m blog hopping&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SiciLinuX Group &#187; Falla in Firefox</title>
		<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-1108</link>
		<dc:creator>SiciLinuX Group &#187; Falla in Firefox</dc:creator>
		<pubDate>Thu, 10 Apr 2008 21:19:28 +0000</pubDate>
		<guid>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-1108</guid>
		<description>[...] Per maggiori informazioni Clicca qui [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Per maggiori informazioni Clicca qui [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MondoByte Blog &#187; Blog Archive &#187; Firefox 2.0.0.12 è già vulnerabile?</title>
		<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-202</link>
		<dc:creator>MondoByte Blog &#187; Blog Archive &#187; Firefox 2.0.0.12 è già vulnerabile?</dc:creator>
		<pubDate>Wed, 13 Feb 2008 14:40:01 +0000</pubDate>
		<guid>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-202</guid>
		<description>[...] Si tratta di un aggiornamento molto importante, perché risolve innanzitutto una prima vulnerabilità (chrome protocol directory traversal), segnalata a fine Gennaio su HiredHacker. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Si tratta di un aggiornamento molto importante, perché risolve innanzitutto una prima vulnerabilità (chrome protocol directory traversal), segnalata a fine Gennaio su HiredHacker. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrea Giuliani &#187; Rilasiato Firefox 2.0.0.12</title>
		<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-111</link>
		<dc:creator>Andrea Giuliani &#187; Rilasiato Firefox 2.0.0.12</dc:creator>
		<pubDate>Fri, 08 Feb 2008 19:12:52 +0000</pubDate>
		<guid>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-111</guid>
		<description>[...] di casa Mozilla che finalmente corregge la vulnerabilità scoperta alla fine del mese di gennaio da Gerry Eisehaur che permetteva di sfruttare gli add-on flat (es. Greasemonkey o Download Statusbar) per eseguire [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] di casa Mozilla che finalmente corregge la vulnerabilità scoperta alla fine del mese di gennaio da Gerry Eisehaur che permetteva di sfruttare gli add-on flat (es. Greasemonkey o Download Statusbar) per eseguire [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quix0r</title>
		<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-110</link>
		<dc:creator>Quix0r</dc:creator>
		<pubDate>Fri, 08 Feb 2008 16:41:51 +0000</pubDate>
		<guid>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-110</guid>
		<description>For Firefox users: Use NoScript and check all(!) settings twice. Then you should be fine against such JS hacks. :) For IE/Opera/Safari users: Keep your browser up-to-date or switch over to FF+NoScript.</description>
		<content:encoded><![CDATA[<p>For Firefox users: Use NoScript and check all(!) settings twice. Then you should be fine against such JS hacks. :) For IE/Opera/Safari users: Keep your browser up-to-date or switch over to FF+NoScript.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Day mobile edition</title>
		<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-103</link>
		<dc:creator>Zero Day mobile edition</dc:creator>
		<pubDate>Fri, 08 Feb 2008 12:31:28 +0000</pubDate>
		<guid>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-103</guid>
		<description>[...] The most notable of the bunch is MFSA 2008-05. This fix covered that vulnerability that allowed an attacker to run off with stored cookies and other data contained in flat files. The vulnerability was discovered by researcher Gerry Eisenhaur. On Jan. 29, Mozilla security chief Window Snyder upgraded the vulnerability and set plans for Firefox 2.0.0.12, which will be pushed out “shortly.” On Jan. 22, Snyder confirmed a proof of concept vulnerability discovered by Eisenhaur on Jan. 19. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] The most notable of the bunch is MFSA 2008-05. This fix covered that vulnerability that allowed an attacker to run off with stored cookies and other data contained in flat files. The vulnerability was discovered by researcher Gerry Eisenhaur. On Jan. 29, Mozilla security chief Window Snyder upgraded the vulnerability and set plans for Firefox 2.0.0.12, which will be pushed out “shortly.” On Jan. 22, Snyder confirmed a proof of concept vulnerability discovered by Eisenhaur on Jan. 19. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firefox il bug diventa ad alto rischio :: News Orebla.it</title>
		<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-54</link>
		<dc:creator>Firefox il bug diventa ad alto rischio :: News Orebla.it</dc:creator>
		<pubDate>Mon, 04 Feb 2008 08:35:52 +0000</pubDate>
		<guid>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-54</guid>
		<description>[...] ufficiale (presente a questa pagina) aveva segnalato sin dal principio che ci sarebbero stati problemi legati anche alla possibilità [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] ufficiale (presente a questa pagina) aveva segnalato sin dal principio che ci sarebbero stati problemi legati anche alla possibilità [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firefox 2.0.0.12 schliesst Sicherheitslücke &#171; Lothars Blog</title>
		<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-47</link>
		<dc:creator>Firefox 2.0.0.12 schliesst Sicherheitslücke &#171; Lothars Blog</dc:creator>
		<pubDate>Fri, 01 Feb 2008 23:21:44 +0000</pubDate>
		<guid>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-47</guid>
		<description>[...] soll Anfang nächster Woche heraus kommen. Es wird wiederum ein Sicherheits Update sein, das ein Loch stopft, das durch die Benutzung bestimmter Erweiterungen entsteht. Bis dahin sollte die Erweiterung [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] soll Anfang nächster Woche heraus kommen. Es wird wiederum ein Sicherheits Update sein, das ein Loch stopft, das durch die Benutzung bestimmter Erweiterungen entsteht. Bis dahin sollte die Erweiterung [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mozilla&#8217;s LiFe</title>
		<link>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-40</link>
		<dc:creator>Mozilla&#8217;s LiFe</dc:creator>
		<pubDate>Thu, 31 Jan 2008 13:34:01 +0000</pubDate>
		<guid>http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/#comment-40</guid>
		<description>[...] possibilità di eseguire un file javascript arbitrariamente su una macchina remota e a scoprirla e segnalarla è stato un utente, Gerry Eisehaur, blogger esperto di [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] possibilità di eseguire un file javascript arbitrariamente su una macchina remota e a scoprirla e segnalarla è stato un utente, Gerry Eisehaur, blogger esperto di [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
