<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>JaBbA's Hut - Browser Wars</title>
    <link>http://jalcorn.net/weblog/</link>
    <description>White Hat Liberal Geek Dad</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.2.1 - http://www.s9y.org/</generator>
    <pubDate>Tue, 03 Oct 2006 14:54:23 GMT</pubDate>

    <image>
        <url>http://jalcorn.net/weblog/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: JaBbA's Hut - Browser Wars - White Hat Liberal Geek Dad</title>
        <link>http://jalcorn.net/weblog/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>FIrefox Flaw?  Maybe...maybe not</title>
    <link>http://jalcorn.net/weblog/archives/1037-FIrefox-Flaw-Maybe...maybe-not.html</link>
            <category>Browser Wars</category>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1037-FIrefox-Flaw-Maybe...maybe-not.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1037</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1037</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    There&#039;s been a lot of uproar over a presentation at &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50b29yY29uLm9yZy8=&amp;amp;entry_id=1037&quot; title=&quot;http://www.toorcon.org/&quot;  onmouseover=&quot;window.status=&#039;http://www.toorcon.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Toorcon&lt;/a&gt; where a pair of &quot;Security Researchers&quot; (which is what they would be called if they used responsible disclosure) / &quot;Hackers&quot; (which is the term almost universally used in press accounts) claimed to have found a bug in Firefox which they used to build a botnet.&lt;br /&gt;
&lt;br /&gt;
This understandably concerned the Mozilla team, and a member of the Mozilla security team joined the presentation.  Turns out they were &quot;joking&quot;.  I&#039;m not sure how the announcement of the creation of a botnet based on a non-existent security flaw constitutes a &quot;joke&quot; - and I&#039;m a geek.  I &quot;get&quot; some pretty esoteric jokes. &lt;img src=&quot;http://jalcorn.net/weblog/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt;  They wanted to tweak the &quot;Firefox fanboys&quot;.  &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2RldmVsb3Blci5tb3ppbGxhLm9yZy9kZXZuZXdzL2luZGV4LnBocC8yMDA2LzEwLzAyL3VwZGF0ZS1wb3NzaWJsZS12dWxuZXJhYmlsaXR5LXJlcG9ydGVkLWF0LXRvb3Jjb24v&amp;amp;entry_id=1037&quot;  onmouseover=&quot;window.status=&#039;http://developer.mozilla.org/devnews/index.php/2006/10/02/update-possible-vulnerability-reported-at-toorcon/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;mozilla.org&quot;&gt;Mischa later apologized&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;he main purpose of our talk was to be humorous.&lt;br /&gt;
&lt;br /&gt;
As part of our talk we mentioned that there was a previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution. However, the code we presented did not in fact do this, and I personally have not gotten it to result in code execution, nor do I know of anyone who has.&lt;br /&gt;
&lt;br /&gt;
I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly havenât used it to take over anyone elseâs computer and execute arbitrary code.&lt;br /&gt;
&lt;br /&gt;
I do not have 30 undisclosed Firefox vulnerabilities, nor did I ever make this claim. I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not.&lt;br /&gt;
&lt;br /&gt;
I apologize to everyone involved, and I hope I have made everything as clear as possible.&lt;br /&gt;
&lt;br /&gt;
Sincerely,&lt;br /&gt;
&lt;br /&gt;
Mischa Spiegelmock&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Nevertheless, there apparently is a little bit of fire in all that smoke - a &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2RldmVsb3Blci5tb3ppbGxhLm9yZy9kZXZuZXdzL2luZGV4LnBocC8yMDA2LzEwLzAyL3VwZGF0ZS1wb3NzaWJsZS12dWxuZXJhYmlsaXR5LXJlcG9ydGVkLWF0LXRvb3Jjb24v&amp;amp;entry_id=1037&quot;  onmouseover=&quot;window.status=&#039;http://developer.mozilla.org/devnews/index.php/2006/10/02/update-possible-vulnerability-reported-at-toorcon/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;mozilla.org&quot;&gt;flaw in Firefox&lt;/a&gt; that can apparently be used for a Denial of service.  Of course, I didn&#039;t say too much about the IE setslice vulnerability on Thursday because it, too, was a DoS bug - until Friday night, when suddenly a remote code execution exploit was released and caused enough havoc to prompt the ISC to &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xNzQ5&amp;amp;entry_id=1037&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1749&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;isc.sans.org&quot;&gt;go to yellow alert&lt;/a&gt;.  So be aware, if I hear of this escalating to an exploit I&#039;ll post asap.&lt;br /&gt;
&lt;br /&gt;
The most important thing - Mozilla immediately reacted, is concerned with finding the truth, not maintaining a corporate image, and is taking this very seriously.  &lt;br /&gt;
&lt;br /&gt;
JaBbA says: Open Source means more than just source code.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 03 Oct 2006 10:54:23 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1037-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Lies, Damn Lies, and Statistics</title>
    <link>http://jalcorn.net/weblog/archives/953-Lies,-Damn-Lies,-and-Statistics.html</link>
            <category>Browser Wars</category>
    
    <comments>http://jalcorn.net/weblog/archives/953-Lies,-Damn-Lies,-and-Statistics.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=953</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=953</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    There&#039;s been a lot of talk in the online media about how Firefox&#039;s &quot;honeymoon&quot; is over.  Articles showing that Firefox has more vulnerabilities than IE have been cropping up frequently.&lt;br /&gt;
&lt;br /&gt;
Most of the articles cite &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zZWN1bmlhLmNvbS8=&amp;amp;entry_id=953&quot; title=&quot;http://www.secunia.com/&quot;  onmouseover=&quot;window.status=&#039;http://www.secunia.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Secunia&lt;/a&gt; for the list of vulnerabilities.  But dig into the numbers, and a different picture emerges.  Secunia lays out all the numbers (see the upper right hand corner of their webpage).   But they summarize it:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;&lt;b&gt;Microsoft Internet Explorer 6.x&lt;/b&gt; with all vendor patches installed and all vendor workarounds applied, is currently affected by one or more Secunia advisories rated &lt;b&gt;Highly critical&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Mozilla Firefox 1.x&lt;/b&gt; with all vendor patches installed and all vendor workarounds applied, is currently affected by one or more Secunia advisories rated &lt;b&gt;Less critical&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Opera 8.x&lt;/b&gt; with all vendor patches installed and all vendor workarounds applied, is currently affected by one or more Secunia advisories rated &lt;b&gt;Not critical&lt;/b&gt;&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
More graphs and charts from Secunia below: &lt;br /&gt;&lt;a href=&quot;http://jalcorn.net/weblog/archives/953-Lies,-Damn-Lies,-and-Statistics.html#extended&quot;&gt;Continue reading &quot;Lies, Damn Lies, and Statistics&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Thu, 29 Dec 2005 08:29:22 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/953-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Simple Anti-Phishing tool</title>
    <link>http://jalcorn.net/weblog/archives/917-Simple-Anti-Phishing-tool.html</link>
            <category>Browser Wars</category>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/917-Simple-Anti-Phishing-tool.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=917</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=917</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    A new firefox extension is a simple and effective addition to the Anti-Fraud arsenal.&lt;br /&gt;
&lt;br /&gt;
The &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3BldG5hbWUubW96ZGV2Lm9yZy8=&amp;amp;entry_id=917&quot; title=&quot;http://petname.mozdev.org/&quot;  onmouseover=&quot;window.status=&#039;http://petname.mozdev.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Petname Extension&lt;/a&gt; simply allows you to assign a descriptive name to any SSL-enabled website, then displays that name whenever it sees that same SSL certificate.&lt;br /&gt;
&lt;br /&gt;
Any browser tricks or redirections will become obvious when you &quot;Pet Name&quot; for the website isn&#039;t displayed.&lt;br /&gt;
&lt;br /&gt;
JaBbA recommends.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;UPDATE&lt;/strong&gt; I probably should have pointed out - this is a very small implementation of a new idea called a &quot;Security Skin&quot;.  See&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zY2huZWllci5jb20vY3J5cHRvLWdyYW0tMDUwNy5odG1sIzEz&amp;amp;entry_id=917&quot; title=&quot;http://www.schneier.com/crypto-gram-0507.html#13&quot;  onmouseover=&quot;window.status=&#039;http://www.schneier.com/crypto-gram-0507.html#13&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt; Bruce Schneier&lt;/a&gt; and &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50eWdhci5uZXQvcGFwZXJzL0JhdHRsZV9hZ2FpbnN0X3BoaXNoaW5nLnBkZg==&amp;amp;entry_id=917&quot; title=&quot;http://www.tygar.net/papers/Battle_against_phishing.pdf&quot;  onmouseover=&quot;window.status=&#039;http://www.tygar.net/papers/Battle_against_phishing.pdf&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;this paper&lt;/a&gt; (PDF). 
    </content:encoded>

    <pubDate>Fri, 15 Jul 2005 14:21:52 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/917-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>New Tool</title>
    <link>http://jalcorn.net/weblog/archives/893-New-Tool.html</link>
            <category>Browser Wars</category>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/893-New-Tool.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=893</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=893</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/netcraft-jabba.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;41&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/netcraft-jabba.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;The &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2h0dHA6Ly90b29sYmFyLm5ldGNyYWZ0LmNvbS9pbnN0YWxs&amp;amp;entry_id=893&quot; title=&quot;http://http://toolbar.netcraft.com/install&quot;  onmouseover=&quot;window.status=&#039;http://http://toolbar.netcraft.com/install&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Netcraft Toolbar&lt;/a&gt; has been an effective anti-phishing tool for IE for some time.  There have been Firefox extensions that had the same idea, but without Netcraft&#039;s information and history.&lt;br /&gt;
&lt;br /&gt;
Now, it&#039;s available for Firefox.  Advantage: No special permissions needed, even if you&#039;re not a power user you can use this tool.&lt;br /&gt;
&lt;br /&gt;
Hmm.  I&#039;m categorized as &quot;Club Software &amp;amp; Computerware&quot;.  Interesting...&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Update&lt;/strong&gt; That&#039;s not a category, that&#039;s the owner of my netblock.  &lt;br /&gt;
&lt;br /&gt;
My Rank is even more interesting...I&#039;m 2 steps below &quot;Tai Whore Sex&quot; but 2 above &quot;nudism.com&quot; &lt;img src=&quot;http://jalcorn.net/weblog/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Another update&lt;/strong&gt; : From &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5pbmZvd29ybGQuY29tL2FydGljbGUvMDUvMDUvMjYvSE5maXJlZm94bmV0Y3JhZnRfMS5odG1sP3NvdXJjZT1yc3MmdXJsPWh0dHA6Ly93d3cuaW5mb3dvcmxkLmNvbS9hcnRpY2xlLzA1LzA1LzI2L0hOZmlyZWZveG5ldGNyYWZ0XzEuaHRtbA==&amp;amp;entry_id=893&quot; title=&quot;http://www.infoworld.com/article/05/05/26/HNfirefoxnetcraft_1.html?source=rss&amp;amp;url=http://www.infoworld.com/article/05/05/26/HNfirefoxnetcraft_1.html&quot;  onmouseover=&quot;window.status=&#039;http://www.infoworld.com/article/05/05/26/HNfirefoxnetcraft_1.html?source=rss&amp;amp;url=http://www.infoworld.com/article/05/05/26/HNfirefoxnetcraft_1.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Infoworld&lt;/a&gt;:&lt;br /&gt;
&lt;blockquote&gt;The free toolbar, released Tuesday, was downloaded more than 60,000 times within hours of its release, according to Netcraft Internet Services Developer Paul Mutton. By comparison, the company&#039;s antiphishing toolbar for Microsoft&#039;s (Profile, Products, Articles) Internet Explorer (IE) browser has been downloaded around 100,000 times since its release earlier this year, he said.&lt;br /&gt;
&lt;br /&gt;
&quot;This seems to indicate that the Firefox community is more interested in security,&quot; Mutton said.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;AND ONE MORE TIME&lt;/strong&gt; :&lt;br /&gt;
&lt;br /&gt;
I found a brand new phishing email, clicked the link and got:&lt;br /&gt;
&lt;a href=&#039;http://jalcorn.net/weblog/uploads/netcraft-block.PNG&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;35&quot; border=&quot;0&quot; hspace=&quot;5&quot; src=&quot;http://jalcorn.net/weblog/uploads/netcraft-block.serendipityThumb.PNG&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
And then:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#039;http://jalcorn.net/weblog/uploads/netcraft-chrome.PNG&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;102&quot; border=&quot;0&quot; hspace=&quot;5&quot; src=&quot;http://jalcorn.net/weblog/uploads/netcraft-chrome.serendipityThumb.PNG&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt; 
    </content:encoded>

    <pubDate>Fri, 27 May 2005 09:26:12 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/893-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Firefox upgrade</title>
    <link>http://jalcorn.net/weblog/archives/548-Firefox-upgrade.html</link>
            <category>Browser Wars</category>
    
    <comments>http://jalcorn.net/weblog/archives/548-Firefox-upgrade.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=548</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=548</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Just noticed the upgrade arrow on my Firefox 1.0.1.&lt;br /&gt;
&lt;br /&gt;
Sure enough, 3 more &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5tb3ppbGxhLm9yZy9wcm9qZWN0cy9zZWN1cml0eS9rbm93bi12dWxuZXJhYmlsaXRpZXMuaHRtbA==&amp;amp;entry_id=548&quot; title=&quot;http://www.mozilla.org/projects/security/known-vulnerabilities.html&quot;  onmouseover=&quot;window.status=&#039;http://www.mozilla.org/projects/security/known-vulnerabilities.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;security fixes&lt;/a&gt; in 1.0.2.&lt;br /&gt;
&lt;br /&gt;
Apparently, at least one is pretty exploitable, having to do with GIF file processing.  Go ahead and get the upgrade.&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 24 Mar 2005 12:30:24 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/548-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Microsoft Responds to the challenge - sort of</title>
    <link>http://jalcorn.net/weblog/archives/544-Microsoft-Responds-to-the-challenge-sort-of.html</link>
            <category>Browser Wars</category>
    
    <comments>http://jalcorn.net/weblog/archives/544-Microsoft-Responds-to-the-challenge-sort-of.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=544</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=544</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Microsoft is &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL25ld3MuY29tLmNvbS9XZWVrK2luK3JldmlldytSZWFkaW5nK1JlZG1vbmQvMjEwMC0xMDgzXzMtNTU4MTcwMy5odG1sP3RhZz1uZWZkLmxlZGU=&amp;amp;entry_id=544&quot; title=&quot;http://news.com.com/Week+in+review+Reading+Redmond/2100-1083_3-5581703.html?tag=nefd.lede&quot;  onmouseover=&quot;window.status=&#039;http://news.com.com/Week+in+review+Reading+Redmond/2100-1083_3-5581703.html?tag=nefd.lede&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;reversing strategy&lt;/a&gt; and is now demonstraing a &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL25ld3MuY29tLmNvbS9NaWNyb3NvZnQrb3V0RmlyZWZveGVkLzIwMTAtMTA3MV8zLTU1ODE0MTguaHRtbA==&amp;amp;entry_id=544&quot; title=&quot;http://news.com.com/Microsoft+outFirefoxed/2010-1071_3-5581418.html&quot;  onmouseover=&quot;window.status=&#039;http://news.com.com/Microsoft+outFirefoxed/2010-1071_3-5581418.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;new Beta for IE7&lt;/a&gt;, coming out long before the next OS release.  Previously, they had tied it closely to the OS releases, and any updates were going to be IE6 patches.&lt;br /&gt;
&lt;br /&gt;
I think they&#039;re worried.  It&#039;s about time.  Reading that article brought back painful memories of the IBM OS/2 debacle. &lt;strong&gt;shudder&lt;/strong&gt; 
    </content:encoded>

    <pubDate>Fri, 18 Feb 2005 13:44:41 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/544-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>A Tale of two browsers</title>
    <link>http://jalcorn.net/weblog/archives/525-A-Tale-of-two-browsers.html</link>
            <category>Browser Wars</category>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/525-A-Tale-of-two-browsers.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=525</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=525</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/1222ebay.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;101&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/1222ebay.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;I received an important email today.  Apparently, my eBay account had an old credit card associated with it.  eBay attempted to verify the card and it was declined.  I better go sign in.&lt;br /&gt;
&lt;br /&gt;
It looks legit.  The email link says https://billing.ebay.com, and the status bar on my Thunderbird says http://billing.ebay.com.  Must be OK.&lt;br /&gt;
&lt;br /&gt;
Except look at the right side of the email&#039;s status bar.  &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#039;http://jalcorn.net/weblog/uploads/1222ebaywarn.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;31&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/1222ebaywarn.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;When I click on the link I have my computer configured with FireFox as my default browser.  It seems to think there&#039;s something odd about the web page I&#039;m going to.  It pops up this warning - something about authenticating to the website.&lt;br /&gt;
&lt;br /&gt;
Well, I&#039;m going to eBay, and I&#039;m going to authenticate, so it must be OK.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#039;http://jalcorn.net/weblog/uploads/1222ebayff.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;69&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/1222ebayff.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;So I get to the website, things flash for a second, and I get a blank screen - and Firefox tells me the website is trying to open a popup.  &lt;br /&gt;
&lt;br /&gt;
Darn popup blockers!  I disable it for the website, and then the screen flashes again.&lt;br /&gt;
&lt;br /&gt;
Darn it, eBay wants me to use IE!  I knew those darn FireFox guys would get something wrong!&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#039;http://jalcorn.net/weblog/uploads/1222ebayie.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;110&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/1222ebayie.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;Well, luckily Microsoft makes sure that IE is on every windows computer.  I fire up IE, cut and paste the address (luckily, I&#039;m a very smart computer user) and I get this screen.  See?  The address bar says https://billing.ebay.com, and the lock on the bottom of my screen assures me that I&#039;m encrypted and that I really am connecting to eBay.&lt;br /&gt;
&lt;br /&gt;
Except that&#039;s not a status bar on the bottom of the screen - it&#039;s an image sent by the malicious website to my browser that LOOKS like an IE status bar.  And it&#039;s using javascript to overlay the address bar with another address.&lt;br /&gt;
&lt;br /&gt;
Nasty. 
    </content:encoded>

    <pubDate>Thu, 23 Dec 2004 02:08:57 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/525-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Hoo, boy.  Another bad IE vulnerability</title>
    <link>http://jalcorn.net/weblog/archives/521-Hoo,-boy.-Another-bad-IE-vulnerability.html</link>
            <category>Browser Wars</category>
    
    <comments>http://jalcorn.net/weblog/archives/521-Hoo,-boy.-Another-bad-IE-vulnerability.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=521</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=521</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/1220ievuln.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;87&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/1220ievuln.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;This screenshot is a fully patched (as of this morning) XP Sp2 machine.  The bar says it&#039;s a paypal SSL site.  The lock is locked.  The certificate is PayPal&#039;s certificate.  EVERYTHING that the browser reports says that you&#039;re looking at Paypal&#039;s site.  The content is Secunia&#039;s test page.&lt;br /&gt;
&lt;br /&gt;
This is VERY VERY BAD.  The test is at &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3NlY3VuaWEuY29tL2ludGVybmV0X2V4cGxvcmVyX2Nyb3NzLXNpdGVfc2NyaXB0aW5nX3Z1bG5lcmFiaWxpdHlfdGVzdC8=&amp;amp;entry_id=521&quot; title=&quot;http://secunia.com/internet_explorer_cross-site_scripting_vulnerability_test/&quot;  onmouseover=&quot;window.status=&#039;http://secunia.com/internet_explorer_cross-site_scripting_vulnerability_test/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Secunia&#039;s site&lt;/a&gt;.  &lt;br /&gt;
&lt;br /&gt;
Right now, there are a couple of defenses against this.&lt;br /&gt;
&lt;br /&gt;
#1 - DO NOT USE IE.  Firefox won&#039;t even allow me to click on the test link.  This is an IE vulnerability, unlike last weeks reports which were Windows vulns.&lt;br /&gt;
&lt;br /&gt;
#2 - NEVER, EVER, trust a link sent to you.  ALWAYS type the address in your browser or use a bookmark you created.  This doesn&#039;t work unless you follow a malicious link.&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 20 Dec 2004 10:22:15 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/521-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Almost All Browsers Vulnerable</title>
    <link>http://jalcorn.net/weblog/archives/511-Almost-All-Browsers-Vulnerable.html</link>
            <category>Browser Wars</category>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/511-Almost-All-Browsers-Vulnerable.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=511</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=511</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/wininjectvuln.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;57&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/wininjectvuln.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;Take a look at the image here.  This is a demonstration from &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zZWN1bmlhLmNvbS8=&amp;amp;entry_id=511&quot; title=&quot;http://www.secunia.com/&quot;  onmouseover=&quot;window.status=&#039;http://www.secunia.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Secunia&lt;/a&gt; of a &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3NlY3VuaWEuY29tL211bHRpcGxlX2Jyb3dzZXJzX3dpbmRvd19pbmplY3Rpb25fdnVsbmVyYWJpbGl0eV90ZXN0Lw==&amp;amp;entry_id=511&quot; title=&quot;http://secunia.com/multiple_browsers_window_injection_vulnerability_test/&quot;  onmouseover=&quot;window.status=&#039;http://secunia.com/multiple_browsers_window_injection_vulnerability_test/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Windows injection vulnerability&lt;/a&gt; that affects most browsers.&lt;br /&gt;
&lt;br /&gt;
The site loaded was the real Citibank website.  There&#039;s a button on the site that pops up information about phishing schemes.  However, Secunia was able to send me to the Citibank site in such a way that when I clicked on the legitimate button, I got a Secunia page instead.&lt;br /&gt;
&lt;br /&gt;
This would fool anyone.  The only way to keep yourself safe from this attack is to make sure you NEVER follow a link.&lt;br /&gt;
&lt;br /&gt;
How does it work?  The Citibank site opens the pop-up, as usual. The attacking website looks for the popup window&#039;s &quot;handle&quot; to appear, then immediately hijacks the window and displays it&#039;s own content - which, of course, could be the exact form you are expecting, but submitting to the attacker instead.  &lt;br /&gt;
&lt;br /&gt;
More information here:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3NlY3VuaWEuY29tL211bHRpcGxlX2Jyb3dzZXJzX3dpbmRvd19pbmplY3Rpb25fdnVsbmVyYWJpbGl0eV90ZXN0Lw==&amp;amp;entry_id=511&quot; title=&quot;http://secunia.com/multiple_browsers_window_injection_vulnerability_test/&quot;  onmouseover=&quot;window.status=&#039;http://secunia.com/multiple_browsers_window_injection_vulnerability_test/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;&lt;img src=&quot;http://secunia.com/gfx/secunia_illustration.jpg&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
There are other demonstrations of similar vulnerabilities on the Secunia site, but this one was the only one that Firefox was COMPLETELY vulnerable to.   The other vulnerabilities have to do with stealing information from dialog boxes like the one shown here and even form fields on other websites.  Firefox was moderately vulnerable to the dialog box hack - at least it kept switching back to the attacker&#039;s website instead of staying on the victim site.  I couldn&#039;t get the form field hack to work in Firefox.&lt;br /&gt;
&lt;br /&gt;
IE is vulnerable to all 3 attacks.&lt;br /&gt;
Opera and Safari are vulnerable to at least 2 of the attacks.&lt;br /&gt;
Firefox/Mozilla are vulnerable to 1 completely and 1 somewhat.&lt;br /&gt;
&lt;br /&gt;
The &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5kZWVwbmV0ZXhwbG9yZXIuY29tLw==&amp;amp;entry_id=511&quot; title=&quot;http://www.deepnetexplorer.com/&quot;  onmouseover=&quot;window.status=&#039;http://www.deepnetexplorer.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Deepnet Explorer&lt;/a&gt; isn&#039;t vulnerable to any of them.  And believe me, they&#039;re telling the world about it.&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Fri, 10 Dec 2004 11:14:02 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/511-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Sweet! - TBird 1.0</title>
    <link>http://jalcorn.net/weblog/archives/509-Sweet!-TBird-1.0.html</link>
            <category>Browser Wars</category>
    
    <comments>http://jalcorn.net/weblog/archives/509-Sweet!-TBird-1.0.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=509</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=509</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/tbirdscreen.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;75&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/tbirdscreen.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;Thunderbird 1.0 is out.  Didn&#039;t get as much &quot;buzz&quot; as Firefox, but this is nice software.&lt;br /&gt;
&lt;br /&gt;
Screenshot shows the new &#039;Grouping&#039; of emails - sort, then group by the sorted column.  Very nice.&lt;br /&gt;
&lt;br /&gt;
Another nice feature - Saved Search folders.  Instead of moving your emails to a folder, run a search, then save the search.  It becomes a &#039;View&#039; of the Inbox, and new messages that meet the search criteria show up in the view.  Why is this important?  Well, a message can appear in more than one View, and new messages appear in the view with no filters!&lt;br /&gt;
&lt;br /&gt;
JaBbA says get it at &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5tb3ppbGxhLm9yZy9wcm9kdWN0cy90aHVuZGVyYmlyZC8=&amp;amp;entry_id=509&quot; title=&quot;http://www.mozilla.org/products/thunderbird/&quot;  onmouseover=&quot;window.status=&#039;http://www.mozilla.org/products/thunderbird/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Mozilla&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Wed, 08 Dec 2004 10:58:11 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/509-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>New Releases</title>
    <link>http://jalcorn.net/weblog/archives/497-New-Releases.html</link>
            <category>Browser Wars</category>
            <category>S9y</category>
    
    <comments>http://jalcorn.net/weblog/archives/497-New-Releases.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=497</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=497</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Firefox 1.0 was released today.  According to &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL25ld3MuYmJjLmNvLnVrLzIvaGkvdGVjaG5vbG9neS8zOTkzOTU5LnN0bQ==&amp;amp;entry_id=497&quot; title=&quot;http://news.bbc.co.uk/2/hi/technology/3993959.stm&quot;  onmouseover=&quot;window.status=&#039;http://news.bbc.co.uk/2/hi/technology/3993959.stm&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;the BBC&lt;/a&gt;:&lt;br /&gt;
&lt;blockquote&gt;Firefox, which was originally called Firebird, also has a growing number of vocal net-based fans.&lt;br /&gt;
&lt;br /&gt;
A campaign co-ordinated by the Spread Firefox website attempted to raise the $50,000 needed for a full page advert in the New York Times.&lt;br /&gt;
&lt;br /&gt;
The campaign set itself a target of recruiting 10,000 volunteers. Ten days in to the campaign 25,000 people had signed up and now about $250,000 has been raised. &lt;/blockquote&gt;&lt;br /&gt;
That&#039;s an impressive amount of loyalty and buzz.  I&#039;ve been using Firefox almost exclusively now for about 9 months, and I&#039;ve found even the betas to be fast, stable and compatible.  And I can&#039;t live without tabbed browsing now!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Also, version 0.7 of the &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zOXkub3JnLw==&amp;amp;entry_id=497&quot; title=&quot;http://www.s9y.org/&quot;  onmouseover=&quot;window.status=&#039;http://www.s9y.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Serendipity Weblog&lt;/a&gt; system has been released.  This is the software that runs this website, and 0.7 is a major update - the biggest feature is the anti-spam stuff and nested/multiple categories, but there&#039;s a nice list on &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2NvZXVzZ3JvdXAuY29tL2VuL2FyY2hpdmVzLzIyNC1TZXJlbmRpcGl0eS0wLjctcmVsZWFzZWQhLmh0bWw=&amp;amp;entry_id=497&quot; title=&quot;http://coeusgroup.com/en/archives/224-Serendipity-0.7-released!.html&quot;  onmouseover=&quot;window.status=&#039;http://coeusgroup.com/en/archives/224-Serendipity-0.7-released!.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Evan&#039;s blog&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Wed, 10 Nov 2004 10:17:17 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/497-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>FireFox 1.0</title>
    <link>http://jalcorn.net/weblog/archives/454-FireFox-1.0.html</link>
            <category>Browser Wars</category>
    
    <comments>http://jalcorn.net/weblog/archives/454-FireFox-1.0.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=454</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=454</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5tb3ppbGxhLm9yZy9wcm9kdWN0cy9maXJlZm94Lw==&amp;amp;entry_id=454&quot; title=&quot;http://www.mozilla.org/products/firefox/&quot;  onmouseover=&quot;window.status=&#039;http://www.mozilla.org/products/firefox/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;&lt;img width=&quot;400&quot; height=&quot;250&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/googlenews.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;Interesting juxtaposition.&lt;br /&gt;
&lt;br /&gt;
As the release of the first 1.0 Preview Release of the FireFox browser began hitting the news, the Microsoft critical vulnerability for the GDI+/JPG problem also hit the news -- and news.google.com happened to put them up at the same time.&lt;br /&gt;
&lt;br /&gt;
I just installed the 1.0PR.  It recognized the extensions I had installed, searched for updated versions, downloaded and installed the one extension that had been updated and informed me that it would keep checking for an update on the other.&lt;br /&gt;
&lt;br /&gt;
JaBbA says &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5tb3ppbGxhLm9yZy9wcm9kdWN0cy9maXJlZm94Lw==&amp;amp;entry_id=454&quot; title=&quot;http://www.mozilla.org/products/firefox/&quot;  onmouseover=&quot;window.status=&#039;http://www.mozilla.org/products/firefox/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;check it out&lt;/a&gt;.   
    </content:encoded>

    <pubDate>Wed, 15 Sep 2004 15:26:08 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/454-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Another eBay scheme, Mozilla updates!</title>
    <link>http://jalcorn.net/weblog/archives/444-Another-eBay-scheme,-Mozilla-updates!.html</link>
            <category>Browser Wars</category>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/444-Another-eBay-scheme,-Mozilla-updates!.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=444</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=444</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&#039;http://jalcorn.net/weblog/uploads/ebay2.jpg&#039;&gt;&lt;img width=&quot;96&quot; height=&quot;110&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/ebay2.serendipityThumb.jpg&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;Another phishing scheme targeting eBay caught today.  Fear, Uncertainty and Doubt is rampant - your account has *already been suspended*!  Do something *immediately*!&lt;br /&gt;
&lt;br /&gt;
The website: signin_ebay_com_account.PoRnOsIn.CoM:7308&lt;br /&gt;
&lt;br /&gt;
The upper and lowercase letters serve to draw your eye away from that, because it makes it look more like the URL, and all you see is &quot;ebay&quot; and &quot;com&quot;.  &lt;br /&gt;
&lt;br /&gt;
Note that the Firefox status bar lowercases the URL, making it easier to see.  Another instance where Firefox is helpful.&lt;br /&gt;
&lt;br /&gt;
Speaking of which, the new Thunderbird client (0.7.3) and the new Firebird (0.9.3) are AWESOME.  Thunderbird now lets you choose to see all your email in plain text format (HOORAY!) and switch back and forth between plain text and HTML with a couple mouse clicks or even a ALT-V-B-H and ALT-V-B-P.&lt;br /&gt;
&lt;br /&gt;
See &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5tb3ppbGxhLm9yZy8=&amp;amp;entry_id=444&quot; title=&quot;http://www.mozilla.org/&quot;  onmouseover=&quot;window.status=&#039;http://www.mozilla.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;mozilla.org&lt;/a&gt; for more information! 
    </content:encoded>

    <pubDate>Thu, 09 Sep 2004 18:00:00 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/444-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>This one is still in SP2</title>
    <link>http://jalcorn.net/weblog/archives/428-This-one-is-still-in-SP2.html</link>
            <category>Browser Wars</category>
    
    <comments>http://jalcorn.net/weblog/archives/428-This-one-is-still-in-SP2.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=428</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=428</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    2 advisories in &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2phbGNvcm4ubmV0L3dlYmxvZy9hcmNoaXZlcy80MjNfQW5vdGhlcitJRVBoaXNoaW5nK3Z1bG5lcmFiaWxpdHkrLStzdGF5K3R1bmVkLmh0bWw=&amp;amp;entry_id=428&quot; title=&quot;http://jalcorn.net/weblog/archives/423_Another+IEPhishing+vulnerability+-+stay+tuned.html&quot;  onmouseover=&quot;window.status=&#039;http://jalcorn.net/weblog/archives/423_Another+IEPhishing+vulnerability+-+stay+tuned.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;3 days for IE&lt;/a&gt;.  &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3NlY3VuaWEuY29tL2Fkdmlzb3JpZXMvMTIzMjEv&amp;amp;entry_id=428&quot; title=&quot;http://secunia.com/advisories/12321/&quot;  onmouseover=&quot;window.status=&#039;http://secunia.com/advisories/12321/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Secunia&lt;/a&gt; has another IE bug - and this one is &#039;Highly Critical&#039;.  &lt;br /&gt;
&lt;br /&gt;
It&#039;s in Active Scripting.  Apparently, a malicious website could drop an executable into your startup folder.  Next time you reboot, wham!  The PoC code requires you to drag-and-drop, but it&#039;s thought that it could be coded to work on the click of a link.&lt;br /&gt;
&lt;br /&gt;
And it&#039;s confirmed in IE 6 on SP1 and SP2.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Fri, 20 Aug 2004 15:16:05 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/428-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Another IE/Phishing vulnerability - stay tuned</title>
    <link>http://jalcorn.net/weblog/archives/423-Another-IEPhishing-vulnerability-stay-tuned.html</link>
            <category>Browser Wars</category>
            <category>Phishing</category>
    
    <comments>http://jalcorn.net/weblog/archives/423-Another-IEPhishing-vulnerability-stay-tuned.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=423</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=423</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    According to a report and proof of concept by &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3NlY3VuaWEuY29tL2ludGVybmV0X2V4cGxvcmVyX2FkZHJlc3NfYmFyX3Nwb29maW5nX3Rlc3RfcG9wdXAv&amp;amp;entry_id=423&quot; title=&quot;http://secunia.com/internet_explorer_address_bar_spoofing_test_popup/&quot;  onmouseover=&quot;window.status=&#039;http://secunia.com/internet_explorer_address_bar_spoofing_test_popup/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Secunia&lt;/a&gt;, a fully patched XP SP1 system is vulnerable to a nasty phishing scheme.&lt;br /&gt;
&lt;br /&gt;
I&#039;m not sure if &quot;rabid&quot; firefox users are actually &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50aGVpbnF1aXJlci5uZXQvP2FydGljbGU9MTc5MTE=&amp;amp;entry_id=423&quot; title=&quot;http://www.theinquirer.net/?article=17911&quot;  onmouseover=&quot;window.status=&#039;http://www.theinquirer.net/?article=17911&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;rejoicing&lt;/a&gt;, but it&#039;s another reason to switch to &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5tb3ppbGxhLm9yZy8=&amp;amp;entry_id=423&quot; title=&quot;http://www.mozilla.org/&quot;  onmouseover=&quot;window.status=&#039;http://www.mozilla.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;something else&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Tue, 17 Aug 2004 10:25:50 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/423-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>

</channel>
</rss>