<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: The Extended HTML Form Attack Revisited</title>
	<atom:link href="http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/feed/" rel="self" type="application/rss+xml" />
	<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/</link>
	<description>Security Consultancy, Research and Development</description>
	<lastBuildDate>Fri, 30 Jul 2010 17:30:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Sandro</title>
		<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/#comment-46</link>
		<dc:creator>Sandro</dc:creator>
		<pubDate>Sun, 13 Jul 2008 22:06:51 +0000</pubDate>
		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=26#comment-46</guid>
		<description>Coaroo: Yes the behavior of various browsers changed from the time that the demo was made and the old demo does not necessarily work. However the vulnerability is still present.</description>
		<content:encoded><![CDATA[<p>Coaroo: Yes the behavior of various browsers changed from the time that the demo was made and the old demo does not necessarily work. However the vulnerability is still present.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Coaroo</title>
		<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/#comment-45</link>
		<dc:creator>Coaroo</dc:creator>
		<pubDate>Sun, 13 Jul 2008 18:02:03 +0000</pubDate>
		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=26#comment-45</guid>
		<description>On your 2002 page, I&#039;ve tested the &quot;demo link&quot; in I.E 6 and Opera 9.50. For the two browsers, I&#039;ve got &quot;error, page not found&quot;, in Opera, it&#039;s clearly stated : &quot;this port is forbidden for security reasons&quot;.</description>
		<content:encoded><![CDATA[<p>On your 2002 page, I&#8217;ve tested the &#8220;demo link&#8221; in I.E 6 and Opera 9.50. For the two browsers, I&#8217;ve got &#8220;error, page not found&#8221;, in Opera, it&#8217;s clearly stated : &#8220;this port is forbidden for security reasons&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Attard</title>
		<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/#comment-31</link>
		<dc:creator>James Attard</dc:creator>
		<pubDate>Tue, 01 Jul 2008 12:35:32 +0000</pubDate>
		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=26#comment-31</guid>
		<description>@Sandro

Yes you&#039;re right. There are many possibilities, and I didn&#039;t foresee that it can also exploit internal services, yet achieving the same results.</description>
		<content:encoded><![CDATA[<p>@Sandro</p>
<p>Yes you&#8217;re right. There are many possibilities, and I didn&#8217;t foresee that it can also exploit internal services, yet achieving the same results.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sandro</title>
		<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/#comment-30</link>
		<dc:creator>Sandro</dc:creator>
		<pubDate>Tue, 01 Jul 2008 11:41:46 +0000</pubDate>
		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=26#comment-30</guid>
		<description>James - I wouldn&#039;t say it only affects the home users. Having a corporate firewall will not block connections to the internal servers (ones behind a firewall). This functionality can be very flexible from an attacker&#039;s point of view ;-)</description>
		<content:encoded><![CDATA[<p>James &#8211; I wouldn&#8217;t say it only affects the home users. Having a corporate firewall will not block connections to the internal servers (ones behind a firewall). This functionality can be very flexible from an attacker&#8217;s point of view ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Attard</title>
		<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/#comment-29</link>
		<dc:creator>James Attard</dc:creator>
		<pubDate>Tue, 01 Jul 2008 09:02:07 +0000</pubDate>
		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=26#comment-29</guid>
		<description>Excellent paper Sandro. This form of attack is especially targeted to home users where firewalls do not exist, or otherwise do not block outgoing ports. About time to think out of the box and not just consider incoming traffic when it comes to securing a home network :)</description>
		<content:encoded><![CDATA[<p>Excellent paper Sandro. This form of attack is especially targeted to home users where firewalls do not exist, or otherwise do not block outgoing ports. About time to think out of the box and not just consider incoming traffic when it comes to securing a home network :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Which ports do web browsers block? &#171; EnableSecurity</title>
		<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/#comment-12</link>
		<dc:creator>Which ports do web browsers block? &#171; EnableSecurity</dc:creator>
		<pubDate>Mon, 23 Jun 2008 11:38:31 +0000</pubDate>
		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=26#comment-12</guid>
		<description>[...] Which ports do web browsers&#160;block? 23Jun08    This is a continuation of the previous post on the subject of HTML forms abuse. [...]</description>
		<content:encoded><![CDATA[<p>[...] Which ports do web browsers&nbsp;block? 23Jun08    This is a continuation of the previous post on the subject of HTML forms abuse. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Formularze HTML nadal niebezpieczne &#124; Pozycjonowanie artykuły - art.mxh.pl</title>
		<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/#comment-10</link>
		<dc:creator>Formularze HTML nadal niebezpieczne &#124; Pozycjonowanie artykuły - art.mxh.pl</dc:creator>
		<pubDate>Mon, 23 Jun 2008 09:11:29 +0000</pubDate>
		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=26#comment-10</guid>
		<description>[...] Gauci z firmy EnableSecurity opublikował w 2002 roku raport na temat zagrożeń wynikających z przesyłania danych za pośrednictwem formularzy HTML. Teraz wydano zaktualizowaną [...]</description>
		<content:encoded><![CDATA[<p>[...] Gauci z firmy EnableSecurity opublikował w 2002 roku raport na temat zagrożeń wynikających z przesyłania danych za pośrednictwem formularzy HTML. Teraz wydano zaktualizowaną [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Coaroo</title>
		<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/#comment-9</link>
		<dc:creator>Coaroo</dc:creator>
		<pubDate>Sat, 21 Jun 2008 15:24:09 +0000</pubDate>
		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=26#comment-9</guid>
		<description>That&#039;s interesting but, as a non-expert, I have trouble to visualize the attack. Would it be possible to have a test page, you know, like there is page to test if your browser is vulnerable to spoofing.
Also, if it&#039;s not possible to solve the problem with the browser, can it be done with the OS ? By closing some ports, for instance ?</description>
		<content:encoded><![CDATA[<p>That&#8217;s interesting but, as a non-expert, I have trouble to visualize the attack. Would it be possible to have a test page, you know, like there is page to test if your browser is vulnerable to spoofing.<br />
Also, if it&#8217;s not possible to solve the problem with the browser, can it be done with the OS ? By closing some ports, for instance ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giannella</title>
		<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/#comment-8</link>
		<dc:creator>Giannella</dc:creator>
		<pubDate>Thu, 19 Jun 2008 16:34:39 +0000</pubDate>
		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=26#comment-8</guid>
		<description>Re [1]:  Yeah I saw that this morning -- and no fix yet 8-(</description>
		<content:encoded><![CDATA[<p>Re [1]:  Yeah I saw that this morning &#8212; and no fix yet 8-(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sandro</title>
		<link>http://enablesecurity.com/2008/06/18/the-extended-html-form-attack-revisited/#comment-7</link>
		<dc:creator>Sandro</dc:creator>
		<pubDate>Thu, 19 Jun 2008 15:32:04 +0000</pubDate>
		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=26#comment-7</guid>
		<description>I think they&#039;re doing a good job on the whole, considering all the attacks coming their way. Firefox has its own set of problems [1] believe me ;-) 

With the flexibility that we have with HTTP, its easy to overlook something like the attack that I (and others have) describe. I&#039;m sure that there are similar scenarios that have not been previously published and that will affect all web browsers because of the nature of the HTTP protocol.

[1] http://blog.mozilla.com/security/2008/06/18/new-security-issue-under-investigation/</description>
		<content:encoded><![CDATA[<p>I think they&#8217;re doing a good job on the whole, considering all the attacks coming their way. Firefox has its own set of problems [1] believe me ;-) </p>
<p>With the flexibility that we have with HTTP, its easy to overlook something like the attack that I (and others have) describe. I&#8217;m sure that there are similar scenarios that have not been previously published and that will affect all web browsers because of the nature of the HTTP protocol.</p>
<p>[1] <a href="http://blog.mozilla.com/security/2008/06/18/new-security-issue-under-investigation/" rel="nofollow">http://blog.mozilla.com/security/2008/06/18/new-security-issue-under-investigation/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
