, 14 2009 . 01:39
+
, 08 2008 . 08:25
+
, 09 2008 . 14:28
+
cyber_alien (
Mozilla_FireFox)
- d'n'b unreleased :X Black Hat, 2 7 . (Itzik Kotler) Radware Black Hat Jinx, - Firefox.
Firefox 3 3.0.1. Jinx . JavaScript , , .. , Windows, Linux Macintosh . .
, " - , - , ". Jinx (., ). , , Radware Jinx- , Microsoft Internet Explorer.
, 09 2008 . 20:30
+
cyber_alien (
Mozilla_FireFox)
Mozilla Site Security Policy (SSP), (XSS), CSRF (Cross Site Request Forgery, , img src , . XSS - , , CSRF , , ). , IFRAME JavaScript, , , web-, web-, .
HTML/JavaScript , iGoogle, eBay, Roxer, Windows Live, MySpace / Facebook Widgets .. SSP Firefox, Web , . SSP , . , ( , ), iframe, javascript src img src.
SSP ( HTTP ):
// script src
X-SSP-Script-Source: allow *.example.com; deny public.example.com
// .
// HEAD HTTP "Policy-Query".
X-SSP-Request-Source: deny * post; allow * get; expires 60
X-SSP-Request-Source: allow *.example.com post,get; deny public.example.com *; expires 3600
X-SSP-Request-Target: allow *.example.com *, deny public.example.com post
// URI POST
X-SSP-Report-URI:
http://www.example.com/policy.cgi
:
OpenNet.ru
SlashDot
Site Security Policy
, 08 2008 . 09:46
+
, 28 2008 . 17:12
+
, 08 2008 . 20:06
+
(
Mozilla_FireFox)
: Mozilla Firefox 2.0.x
, XSS , DoS , .
1) - . .
2) - Javascript. .
.
3) - , . .
4) - Javascript. Javascript "chrome".
5) - Javascript. "XMLDocument.load()", .
6) - , , "designMode". , .
.
7) - , . , .
8) - , Firefox "302" URL "element.sheet.href". URL.