<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Developer&#039;s Mind &#187; Security Exploits</title>
	<atom:link href="http://developersmind.com/category/security-exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://developersmind.com</link>
	<description>Creative Rumblings of a Workaholic Developer!</description>
	<lastBuildDate>Tue, 27 Jul 2010 15:10:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1-alpha</generator>
		<item>
		<title>WordPress 2.8.2 Fixes XSS Vulnerability</title>
		<link>http://developersmind.com/2009/07/21/wordpress-2-8-2-released-fixes-xss-exploit/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=wordpress-2-8-2-released-fixes-xss-exploit</link>
		<comments>http://developersmind.com/2009/07/21/wordpress-2-8-2-released-fixes-xss-exploit/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 14:15:32 +0000</pubDate>
		<dc:creator>Pete Mall</dc:creator>
				<category><![CDATA[Security Exploits]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://www.developersmind.com/?p=85</guid>
		<description><![CDATA[WordPress 2.8.2 was released on Monday, July 20 which patches a known XSS vulnerability. The URLs for the commenters(comment authors) were not fully sanitized before being displayed in the admin area which could be exploited to redirect from the admin area to another site. <a href="http://developersmind.com/2009/07/21/wordpress-2-8-2-released-fixes-xss-exploit/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>WordPress 2.8.2 was released on Monday, July 20 which patches a known XSS vulnerability. The URLs for the commenters(comment authors) were not fully sanitized before being displayed in the admin area which could be exploited to redirect from the admin area to another site. It is recommended to download and upgrade to <a title="Download WordPress" href="http://wordpress.org/download/">version 2.8.2</a> or use the automatic upgrade function of WordPress under Tools &gt; Upgrade from the admin area.</p>
]]></content:encoded>
			<wfw:commentRss>http://developersmind.com/2009/07/21/wordpress-2-8-2-released-fixes-xss-exploit/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>JIT Fixed in Firefox 3.5.1, New Vulnerability Exposed</title>
		<link>http://developersmind.com/2009/07/19/jit-fixed-in-firefox-3-5-1-new-vulnerability-exposed/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=jit-fixed-in-firefox-3-5-1-new-vulnerability-exposed</link>
		<comments>http://developersmind.com/2009/07/19/jit-fixed-in-firefox-3-5-1-new-vulnerability-exposed/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 04:16:55 +0000</pubDate>
		<dc:creator>Pete Mall</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Security Exploits]]></category>

		<guid isPermaLink="false">http://www.developersmind.com/?p=71</guid>
		<description><![CDATA[Firefox 3.5.1 was released on Friday, July 17 which included a patch for the Just-in-time (JIT) JavaScript compiler exploit. However, a new stack-based buffer overflow vulnerability has been exposed with sample exploit code. An attacker can cause a buffer overflow and &#8230; <a href="http://developersmind.com/2009/07/19/jit-fixed-in-firefox-3-5-1-new-vulnerability-exposed/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Firefox 3.5.1 was released on Friday, July 17 which included a patch for the <a title="JIT Exploit in Firefox 3.5" href="http://www.developersmind.com/security-exploits/critical-javascript-exploit-surfaces-in-firefox-3-5">Just-in-time (JIT) JavaScript compiler exploit</a>. However, a new stack-based buffer overflow vulnerability has been exposed with sample <a title="Sample Exploit Code" href="http://downloads.securityfocus.com/vulnerabilities/exploits/35707.html">exploit code</a>. An attacker can cause a buffer overflow and execute arbitrary code by sending a very long unicode string to the <code>document.write</code> JavaScript method.</p>
<p>Currently, there is no patch for this vulnerability. The NoScript Add-On will not help against this exploit because this vulnerability may be exploited if an untrusted site is loaded using XSS or a compromised white-listed site.</p>
<p>Mozilla has acknowledged the vulnerability, but claims that it cannot be exploited. Mike Shaver wrote the following on the Mozilla Security Blog:</p>
<blockquote><p>&#8220;In the last few days, there have been several reports of a bug in Firefox related to handling of certain very long Unicode strings. While these strings can result in crashes of some versions of Firefox, the reports by press and various security agencies have incorrectly indicated that this is an exploitable bug. Our analysis indicates that it is not, and we have seen no example of exploitability.&#8221;</p>
</blockquote>
<p><a href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fdevelopersmind.com%2F2009%2F07%2F19%2Fjit-fixed-in-firefox-3-5-1-new-vulnerability-exposed%2F&amp;linkname=JIT%20Fixed%20in%20Firefox%203.5.1%2C%20New%20Vulnerability%20Exposed" title="Twitter" rel="nofollow" target="_blank"><img src="http://developersmind.jointforcestech.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a> <a href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fdevelopersmind.com%2F2009%2F07%2F19%2Fjit-fixed-in-firefox-3-5-1-new-vulnerability-exposed%2F&amp;linkname=JIT%20Fixed%20in%20Firefox%203.5.1%2C%20New%20Vulnerability%20Exposed" title="Facebook" rel="nofollow" target="_blank"><img src="http://developersmind.jointforcestech.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a> <a href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fdevelopersmind.com%2F2009%2F07%2F19%2Fjit-fixed-in-firefox-3-5-1-new-vulnerability-exposed%2F&amp;linkname=JIT%20Fixed%20in%20Firefox%203.5.1%2C%20New%20Vulnerability%20Exposed" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://developersmind.jointforcestech.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a> <a href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fdevelopersmind.com%2F2009%2F07%2F19%2Fjit-fixed-in-firefox-3-5-1-new-vulnerability-exposed%2F&amp;linkname=JIT%20Fixed%20in%20Firefox%203.5.1%2C%20New%20Vulnerability%20Exposed" title="Digg" rel="nofollow" target="_blank"><img src="http://developersmind.jointforcestech.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a> <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save">Share</a> </p>]]></content:encoded>
			<wfw:commentRss>http://developersmind.com/2009/07/19/jit-fixed-in-firefox-3-5-1-new-vulnerability-exposed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Critical JavaScript Vulnerability Surfaces in Firefox 3.5</title>
		<link>http://developersmind.com/2009/07/15/critical-javascript-exploit-surfaces-in-firefox-3-5/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=critical-javascript-exploit-surfaces-in-firefox-3-5</link>
		<comments>http://developersmind.com/2009/07/15/critical-javascript-exploit-surfaces-in-firefox-3-5/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 14:38:08 +0000</pubDate>
		<dc:creator>Pete Mall</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Security Exploits]]></category>

		<guid isPermaLink="false">http://www.developersmind.com/?p=47</guid>
		<description><![CDATA[Firefox 3.5 boasts of screaming fast JavaScript performance -- almost twice as fast as Firefox 3. Firefox 3.5 attributes its dramatically better JavaScript performance to the TraceMonkey Just-in-time (JIT) JavaScript compiler. However, a serious remote buffer overflow security exploit was discovered last week in Firefox 3.5’s Just-in-time (JIT) JavaScript compiler, which enables the execution of malicious code. <a href="http://developersmind.com/2009/07/15/critical-javascript-exploit-surfaces-in-firefox-3-5/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Firefox 3.5 boasts of <em>screaming fast</em> JavaScript performance &#8212; almost twice as fast as Firefox 3. Firefox 3.5 attributes its dramatically better JavaScript performance to the TraceMonkey Just-in-time (JIT) JavaScript compiler. However, a serious remote buffer overflow security exploit was discovered last week in Firefox 3.5’s Just-in-time (JIT) JavaScript compiler, which enables the execution of malicious code.</p>
<p>An attacker can trick a victim to view a webpage containing the exploit code, thereby infecting the victim&#8217;s machine. Fortunately, the JIT JavaScript compiler can be disabled. Type <code>about:config</code> in the location bar and <code>jit</code> in the filter on the config page. Double click <code>javascript.options.jit.content</code> to set the value to false to disable JIT. You can also disable JIT by running Firefox in Safe Mode. You will see a drastic decrease in JavaScript performance by disabling JIT but you can enable it, when this exploit is patched, by setting the javascript.options.jit.content to true.</p>
<div class="wp-caption aligncenter" style="width: 564px"><img title="Disable JIT in Firefox 3.5" src="http://www.developersmind.com/wp-content/uploads/2009/07/Picture-3.png" alt="Disable JIT in Firefox 3.5" width="554" height="323" /><p class="wp-caption-text">Disable JIT in Firefox 3.5</p></div>
<p>The security exploit has already been patched in nightly build 3.6 on July 14 available <a title="Firefox nightly builds" href="http://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/latest-trunk/" target="_blank">here</a>. The patch will be a part of the 3.5.x release which was initially scheduled for the end of July but has been moved up.</p>
]]></content:encoded>
			<wfw:commentRss>http://developersmind.com/2009/07/15/critical-javascript-exploit-surfaces-in-firefox-3-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
