<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Mozilla Firefox</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/mozilla-firefox//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Start Firefox with multiple homepage</title>
		<link>http://42.kaizeku.com/firefox/start-firefox-with-multiple-homepage/</link>
		<comments>http://42.kaizeku.com/firefox/start-firefox-with-multiple-homepage/#comments</comments>
		<pubDate>Sat, 12 Jul 2008 15:03:26 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/?p=244</guid>
		<description><![CDATA[

Do you like looking at the Google search (default homepage) every time you open your Firefox or do want Firefox to open all your favorites visited website when its start?. 
Learn how to set Firefox to open multiple homepage on start-up with this few simple step.




Open Firefox goto Tools &#187; Options (for *nix try Edit [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://blog.kakkoi.net/wp-content/uploads/2008/07/firefox-tips-and-tricks-pinpreview-by-chaoskaizer.png" alt="firefox tips and tricks" title="firefox-tips-and-tricks-pinup-preview-by-chaoskaizer" width="128" height="128" class="alignleft size-full wp-image-249" />Do you like looking at the Google search (default homepage) every time you open your <a href="http://www.mozilla.com/en-US/firefox/" title="Firefox">Firefox</a> or do want Firefox to open all your favorites visited website when its start?. </p>
<p>Learn how to set Firefox to open multiple homepage on start-up with this few simple step.</p>
<p><span id="more-244"></span><br />
<a href='http://blog.kakkoi.net/firefox/start-firefox-with-multiple-homepage/attachment/firefox-open-multiple-website-on-startup/' rel="attachment wp-att-245"><img src="http://blog.kakkoi.net/wp-content/uploads/2008/07/firefox-open-multiple-website-on-startup.png" alt="firefox" title="firefox-open-multiple-website-on-startup" width="400" height="245" class="aligncenter size-full wp-image-245" /></a></p>
<ol class="xoxo mgb">
<li>
<p>Open Firefox goto <tt>Tools &raquo; Options</tt> (for *nix try Edit &raquo; Preferences )</p>
<p><a href='http://blog.kakkoi.net/firefox/start-firefox-with-multiple-homepage/attachment/firefox-options-main-tab/' rel="attachment wp-att-246"><img src="http://blog.kakkoi.net/wp-content/uploads/2008/07/firefox-options-main-tab.png" alt="Firefox tool options" title="firefox-options-main-tab" width="328" height="327" class="alignnone size-full wp-image-246" /></a></li>
<li>Select the &#8220;<strong>Main</strong>&#8221; tab</li>
<li>
<p> On the <strong>Homepage</strong> option add your favorite <strong>website URL</strong> or <strong>Keywords</strong>. Separate the URLs with the pipe <tt class="hilite-2">|</tt> characters like the below example &darr;</p>
<pre class="smallbox"> http://google.com|digg|delicious</pre>
<p><a href='http://blog.kakkoi.net/firefox/start-firefox-with-multiple-homepage/attachment/firefox-options-main-tab-set-homepage/' rel="attachment wp-att-247"><img src="http://blog.kakkoi.net/wp-content/uploads/2008/07/firefox-options-main-tab-set-homepage.png" alt="firefox homepage options" title="firefox-options-main-tab-set-homepage" width="375" height="374" class="alignnone size-full wp-image-247" /></a>
</li>
<li> Ok you are done the next time Firefox start it will load all the website.</li>
</ol>
<h2>Where do I add the keywords?</h2>
<p>Keywords are special tag for URL shortcut, bookmarks manager (ctrl+b). </p>
<p><a href='http://blog.kakkoi.net/firefox/start-firefox-with-multiple-homepage/attachment/firefox-bookmark-keywords/' rel="attachment wp-att-248"><img src="http://blog.kakkoi.net/wp-content/uploads/2008/07/firefox-bookmark-keywords.png" alt="firefox add bookmar" title="firefox-bookmark-keywords" width="337" height="249" class="alignnone size-full wp-image-248" /></a></p>
<h2>Might be interest</h2>
<ul class="xoxo">
<li><a href="http://support.mozilla.com/en-US/kb/Options+window">Mozilla KB - Options Window</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/start-firefox-with-multiple-homepage/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firebug For Firefox 3</title>
		<link>http://42.kaizeku.com/firefox/firebug-for-firefox-3-release-candiate/</link>
		<comments>http://42.kaizeku.com/firefox/firebug-for-firefox-3-release-candiate/#comments</comments>
		<pubDate>Fri, 23 May 2008 04:33:18 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Firefox Add-ons]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[addons]]></category>

		<category><![CDATA[firebug]]></category>

		<category><![CDATA[firefox3]]></category>

		<category><![CDATA[yslow]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/firefox/firebug-for-firefox-3-release-candiate/</guid>
		<description><![CDATA[

After 6 months waiting Firebug 1.2 is out.

 Firebug 1.2x stable release support all major Firefox version (Firefox 2.0.0.14 > Firefox 3 RC but not recommended for Firefox 3.0b5) . Compatible with Latest Firefox 3 RC 1. 
Download Firebug 1.2x

Firebug 1.2x

Whats new in Firebug 1.2x
Latest version is more friendly and all suppose to be disabled [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<blockquote class="fr" style="width:30%" cite="http://blog.kakkoi.net/mozila-firefox/firebug"><p>After 6 months waiting Firebug 1.2 is out.</p>
</blockquote>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-for-firefox-3.png' alt='firebug for firefox 3' width="128" height="128" class="photo thumb- fl"/> <a href="http://en.wikipedia.org/wiki/Firebug_(Firefox_extension)"><strong>Firebug 1.2x</strong></a> stable release support all major Firefox version <small>(Firefox 2.0.0.14 > Firefox 3 RC but not recommended for Firefox 3.0b5)</small> . Compatible with Latest <strong>Firefox 3 RC 1.</strong> </p>
<h2 class="cb mgb- " title="Download Firebug 1.2x">Download Firebug 1.2x</h2>
<ul class="xoxo exturl pdt">
<li><a href="http://getfirebug.com/releases/">Firebug 1.2x</a></li>
</ul>
<h3 class="mgt ">Whats new in Firebug 1.2x</h3>
<p>Latest version is more friendly and all suppose to be disabled behaviour is turn off by default. This new change will make sure that you wont have problem with high Ajax framework website (i.e., Google Gmail, Msn Live).</p>
<ul class="xoxo">
<li>Improve performance - most of the automate HTTP reporting is disabled by default <small>( for all site)</small>.</li>
<li><em>Firebug Script</em> and <em>Net panels</em> disabled by default.</li>
<li>More accurate Net reporting and Faster Javascript Debugging.</li>
</ul>
<p>Check out firebug 1.2 <a href="http://blog.kakkoi.net/firefox/firebug-for-firefox-3-release-candiate#firebug-release-notes" title="firebug release notes">release notes</a>,<a href="http://blog.kakkoi.net/firefox/firebug-for-firefox-3-release-candiate#firebug-screenshot" title="screenshot">screenshot</a>, <a href="http://blog.kakkoi.net/firefox/firebug-for-firefox-3-release-candiate#firebug-fixes" title="bug fixes &amp; improvement">bug fixes &amp; improvement</a>.<br />
<span id="more-235"></span></p>
<hr/>
<h2 class="mgt" id="firebug-screenshot">Firebug Screenshot</h2>
<p>Firebug 1.2 on Firefox 3 RC1.</p>
<h4>Firebug Console</h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-console.gif' alt='Firebug Console' /></p>
<h4 class="cb pdt">Firebug Net Panel Disabled by Default</h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-net-panel-disabled.gif' alt='Firebug Net Panel Disabled' /></p>
<h4 class="cb pdt">Firebug Net Panel Enabled</h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-net-panel-enabled.gif' alt='firebug-net-panel-enabled.gif' /></p>
<h4 class="cb pdt">Firebug JIT Script Debugger </h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-debugger-enabled.gif' alt='Firebug Debugger Enabled' /></p>
<h4 class="cb pdt">Firebug CSS Panel </h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-css-panel.gif' alt='Firebug CSS Panel' /></p>
<h4 class="cb pdt">Firebug HTML Panel </h4>
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/05/firebug-html-panel.gif' alt='Firebug HTML Panel' class="mgb cf" /></p>
<hr class="cb mgt mgb"/>
<h3 class="title- mgt mgb- cb" id="firebug-fixes">Firebug 1.2x Bug Fixes &amp; Improvements</h3>
<ol class="dn">
<li>Issue 1: Reload external Firebug window while its tab is hidden closes the window</li>
<li>Issue 2: Can&#8217;t set breakpoints in code called by unload event</li>
<li>Issue 4: Visiting error page causes external Firebug window to close itself</li>
<li>Issue 7 Long URLs in XHR spy rows should be cropped</li>
<li>Issue 14: Programatically disable firebug log from Javascript</li>
<li>Issue 38: console.group should allow optional collapse</li>
<li>Issue 43: Edit CSS behaviour - appending styles to the dom is unexpected. Contribution by tonygentilcore</li>
<li>Issue 65 show HTTP Status code on NET response</li>
<li>Issue 183: Configurable maximum output size</li>
<li>Issue 186 Only one line in net monitor for multiple xhr post requests</li>
<li>Issue 202 Clicking status bar error warning closes firebug</li>
<li>Issue 215 Display total page load time </li>
<li>Issue 216 Improve network monitor to include server-side processing time</li>
<li>Issue 266 PUT &#038; DELETE requests appear as POST requests in firebug</li>
<li> Issue 316 Show HTTP request method and request content in Firebugs &#8220;Net&#8221; tab</li>
<li>Issue 325 PUT operations do not show contained entity in Net tab</li>
<li> Issue 327 &#8220;Net&#8221; tab: lowercase b for bytes (instead of B)</li>
<li>Issue 331 XHR resolves relative URIs to resource:// protocol</li>
<li> Issue 346 Fix Net Panel timings</li>
<li>Issue 349 Local file XHR events not listed in console</li>
<li> Issue 359 No entry in the Net tab for XHR when response content length is 0</li>
<li>Issue 361: Edit button gets stuck when reloading page whilst editing CSS. Contribution by tonygentilcore</li>
<li> Issue 393: Text overlayed on text in script editor window.</li>
<li>Issue 401 Net tab does not consider &#8220;application/javascript&#8221; a JS MIME type</li>
<li> Issue 402 Net tab tries to show previews of non-images with image file extensions</li>
<li> Issue 404 UI change to help users activate expensive debugging features only when they need them.</li>
<li>Issue 405 The Net panel consumes a lot of memory if there is a lot of XHR activity without page reload.</li>
<li>Issue 414 XHR Breaks When Using Firebug 1.1 beta when > 1 HTTP 302 Redirect Is Returned</li>
<li>Issue 421 onLoad of XHRSpyListener does not fire correctly</li>
<li> Issue 430 about:blank pages always show firebug as enabled</li>
<li>Issue 468 [feature request] fast [enable -> inspect element -> disable] ergonomy</li>
<li> Issue 474: base href applied to scripts</li>
<li> Issue 475 Show Return Code (HTTP HEADER-Response)</li>
<li>Issue 503 disable doesn&#8217;t work properly</li>
<li> Issue 567: Slow script warning in debugger.js on some pages</li>
<li> Issue 573: setting css background-color affects layout inspector. Contribution by tonygentilcore</li>
<li>Issue 583 Javascript console cannot work with Firefox 3 beta5</li>
<li> issue 599, Firebug Inspect Outline Does Not Show Up Over Web Page Elements</li>
<li> Issue 601 XHR in console shows stale/cached output</li>
<li> Issue 618: HTML: tab order, fixed by setting order properties on side panels.</li>
<li> Issue 619: Reopening firebug results in grey DOM, Layout or Style Pane, fixed by forceUpdate on syncSidePanel.</li>
<li> Issue 634 XHR request details not showing up</li>
<li> Issue 637 $ FireBug function overwrites existing $ function</li>
<li> Issue 659: firebug.js:1473 - &#8220;this.context.browser is undefined&#8221;</li>
<li> Issue 676 Exception in firebug-cache.js when visiting http://www.takebacktheweb.org/CaE.html</li>
<li> Issue 679 Firebug 1.2.0a27X blocking most AJAX calls</li>
<li> Issue 690 New zh-CN local file for Firebug 1.2</li>
</ol>
<h2 class="mgt pdt mgb-">External Links</h2>
<ul class="xoxo exturl">
<li><a id="firebug-release-notes" href="http://code.google.com/p/fbug/source/browse/branches/firebug1.2/docs/ReleaseNotes_1.2.txt" title="Firebug 1.2x Release Notes">Firebug 1.2x Release Notes</a></li>
<li><a href="http://code.google.com/p/fbug/" title="Firebug at Google Code">Firebug at Google Code</a></li>
<li><a href="http://www.getfirebug.com/">Official Firebug Website</a></li>
<li><a href="http://developer.yahoo.com/yslow/" title="Firebug addon YSlow" class="ext">Yslow</a<cite>YSlow analyzes web pages and tells you why they&#8217;re slow based on the rules for high performance web sites. YSlow is a Firefox add-on integrated with the popular Firebug web development too</cite></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/firebug-for-firefox-3-release-candiate/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox 2.0.0.12 Information Leak</title>
		<link>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/</link>
		<comments>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/#comments</comments>
		<pubDate>Sun, 10 Feb 2008 11:21:37 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/exploit/firefox-20012-information-leak-vulnerability/</guid>
		<description><![CDATA[

We are going to see Firefox 2.0.0.13 probably by end of this week. Check out this directory transversal code using view-sources: &#038; resource: scheme
view-source:resource:///
translate to file:///C:/Program%20Files/Mozilla%20Firefox/
You can read/include firefox pref settings with this code. &#60;script src=&#8221;view-source:resource:///greprefs/all.js&#8221;&#62;&#60;/script&#62; 
Workaround
Install No-script Add-ons.

Credits
Ronald van den Heetkamp at 0&#215;000000
External Links

Firefox 2.0.0.12 Information Leak POC


]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg' alt='Marvin Apbot costume by chaoskaizer' width="100" height="100" longdesc="http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2007/12/marvin-apbot-costume-by-chaoskaizer.jpg" />We are going to see Firefox 2.0.0.13 probably by end of this week. Check out this directory transversal code using view-sources: &#038; resource: scheme<br />
<tt class="di">view-source:resource:///</tt><br />
translate to <tt class="di">file:///C:/Program%20Files/Mozilla%20Firefox/</tt></p>
<p>You can read/include firefox pref settings with this code. <tt>&lt;script src=&#8221;view-source:resource:///greprefs/all.js&#8221;&gt;&lt;/script&gt; </tt></p>
<h2 class="cb">Workaround</h2>
<p>Install <a class="exturl icn-r1" href="http://noscript.net/">No-script</a> Add-ons.</p>
<p><span id="more-197"></span></p>
<h2>Credits</h2>
<p><span class="vcard"><a class="url fn microformat icn-r1" href="http://www.0x000000.com/index.php?!=6"><span class="given-name">Ronald</span> <span class="family-name">van den Heetkamp</span></a> at <a class="url org exturl icn-r1" href="http://www.0x000000.com">0&#215;000000</a></span></p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r1" href="http://www.0x000000.com/index.php?i=515">Firefox 2.0.0.12 Information Leak POC</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/exploit/firefox-20012-information-leak-vulnerability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox 2.0.0.12 Security Release</title>
		<link>http://42.kaizeku.com/firefox/firefox-20012-security-release/</link>
		<comments>http://42.kaizeku.com/firefox/firefox-20012-security-release/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 15:45:48 +0000</pubDate>
		<dc:creator>chaoskaizer.myopenid.com</dc:creator>
		
		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Web Browsers]]></category>

		<category><![CDATA[browser]]></category>

		<category><![CDATA[cve]]></category>

		<category><![CDATA[gecko]]></category>

		<category><![CDATA[javascript]]></category>

		<category><![CDATA[thunderbird]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/firefox/firefox-20012-security-release/</guid>
		<description><![CDATA[

Firefox 2.0.0.12 Security Update fixes 7 Vulnerability &#38; 3 critical patch (memory corruption, JavaScript Engine Crashes).

 Known Vulnerabilities in Mozilla Products (Firefox 2.0.0.11) 

MFSA 2008-11

Web forgery overwrite with div overlay

Descriptions
Security researchers Emil Ljungdahl and Lars-Olof Moilanen demonstrated that, in cases where the entire contents of a page are enclosed in a &#60;div&#62; with absolute positioning, [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><a class="exturl icn-r1" href="http://www.mozilla.com/en-US/firefox/all.html"><strong>Firefox 2.0.0.12</strong></a> Security Update fixes <a class="exturl icn-r" href="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.12">7 Vulnerability &amp; 3 critical patch</a> (memory corruption, <a class="exturl icn-r1" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087">JavaScript Engine Crashes</a>).<br />
<span id="more-192"></span></p>
<h2 id="firefox2.0.0.12" class="cb"> Known Vulnerabilities in Mozilla Products (Firefox 2.0.0.11) </h2>
<dl class="xoxo def">
<dt class="b1t-"><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-11.html">MFSA 2008-11</a></dt>
<dd class="b1t-">
<h3 class="title- mg-">Web forgery overwrite with div overlay</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researchers <em>Emil Ljungdahl</em> and <em>Lars-Olof Moilanen</em> demonstrated that, in cases where the entire contents of a page are enclosed in a <tt class="di">&lt;div&gt;</tt> with absolute positioning, a web forgery warning dialog won&#8217;t be displayed unless the user switches tabs away-from then back-to the forgery page.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a rel="nofollow" class="exturl icn-r1" title="Web forgery warning not shown until tab switch" href="https://bugzilla.mozilla.org/show_bug.cgi?id=408164">Web forgery warning not shown until tab switch</a>
</li>
<li><a rel="nofollow" class="exturl icn-r1" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0594">National Vulnerability Database (NVD) - CVE-2008-0594</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-10.html">MFSA 2008-10</a></dt>
<dd>
<h3 class="title- mg-">URL token stealing via stylesheet redirect</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researcher <em>Martin Straka</em> reported that <strong>Gecko-based browsers</strong> update the <tt class="di">.href</tt> property of stylesheet DOM nodes to reflect the final URI of the stylesheet after following any 302 redirects (much as the <tt class="di">document.location</tt> property is updated). This differs from other browsers and could potentially reveal sensitive URL parameters, such as those used by Single-signon sytems, to scripts on the page.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Stylesheet href property shows redirected URL unlike other browsers" href="https://bugzilla.mozilla.org/show_bug.cgi?id=397427">Stylesheet href property shows redirected URL unlike other browsers</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0593">National Vulnerability Database (NVD) - CVE-2008-0593</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-09.html">MFSA 2008-09</a></dt>
<dd>
<h3 class="title- mg-">Mishandling of locally-saved plain text files</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributor <em>oo.rio.oo</em> demonstrated that once a file with <tt class="di">Content-Disposition: attachment</tt> and (improper) <tt class="di">Content-Type: plain/text</tt> is saved locally, the browser would no longer open local files with <tt class="di">.txt</tt> extensions for viewing, but would rather prompt the user to save the file.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="plain text txt file viewing capability lost after having downloaded a txt file" href="https://bugzilla.mozilla.org/show_bug.cgi?id=387258">plain text txt file viewing capability lost after having downloaded a txt file with content-disposition: attachment and content-type: plain/text</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0592">National Vulnerability Database (NVD) - CVE-2008-0592</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-08.html">MFSA 2008-08</a></dt>
<dd>
<h3 class="title- mg-">File action dialog tampering</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researcher <em>Michal Zalewski</em> demonstrated that timer-enabled security dialogs can be subverted by attackers using JavaScript to change the window focus. Zalewski showed that a user could be tricked into confirming a security dialog of this type by bringing the dialog back into focus right before a user clicked in a predictable time and place.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="file action dialog controls vulnerable to refocus race" href="https://bugzilla.mozilla.org/show_bug.cgi?id=376473">file action dialog controls vulnerable to refocus race</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0591">National Vulnerability Database (NVD) - CVE-2008-0591</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-06.html">MFSA 2008-06</a></dt>
<dd>
<h3 class="title- mg-">Web browsing history and forward navigation stealing</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributor <em>David Bloom</em> reported a vulnerability in the way images are treated by the browser when a user leaves a page which utilizes <tt class="di">designMode</tt> frames. The reported issue can be used to steal a user&#8217;s navigation history, forward navigation information, and crash the user&#8217;s browser. The crash showed evidence of memory corruption and might be exploitable to run arbitrary code.<br />
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Vulnerability allows script to see where user is headed, sniff history, and crash nsDocShell::Destroy() the browser too" href="https://bugzilla.mozilla.org/show_bug.cgi?id=400556">Vulnerability allows script to see where user is headed, sniff history, and crash [@ nsDocShell::Destroy()] the browser too</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0419">National Vulnerability Database (NVD) - CVE-2008-0419</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 high" href="http://www.mozilla.org/security/announce/2008/mfsa2008-05.html">MFSA 2008-05</a></dt>
<dd>
<h3 class="title- mg-">Directory traversal via chrome: URI</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p><em>Gerry Eisenhaur</em> reported the chrome: URI scheme improperly allowed directory traversal that could be used to load JavaScript, images, and stylesheets from local files in known locations. This traversal was possible only when the browser had installed add-ons which used &#8220;flat&#8221; packaging rather than the more popular .jar packaging, and the attacker would need to target that specific add-on.</p>
<p>Mozilla researcher <strong>moz_bug_r_a4</strong> reported that this vulnerability could be used to steal the contents of the browser&#8217;s <tt class="di">sessionstore.js</tt> file, which contains session cookie data and information about currently open web pages.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Allows to steal data from sessionstore.js" href="https://bugzilla.mozilla.org/show_bug.cgi?id=413451">Allows to steal data from sessionstore.js</a></li>
<li><a class="exturl icn-r1" title="chrome directory traversal (local disk access via flat addons)" href="https://bugzilla.mozilla.org/show_bug.cgi?id=413250">chrome directory traversal (local disk access via &#8220;flat&#8221; addons)</a></li>
<li><a class="exturl icn-r1" title="list of flat packaged add-ons" href="https://bugzilla.mozilla.org/attachment.cgi?id=300181">list of &#8220;flat&#8221; packaged add-ons</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0418">National Vulnerability Database (NVD) - CVE-2008-0418</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-04.html">MFSA 2008-04</a></dt>
<dd>
<h3 class="title- mg-">Stored password corruption</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla developer <em>Justin Dolske</em> discovered that malicious sites, upon a user saving his or her password, could inject newlines into Firefox&#8217;s password store and corrupt saved passwords for other sites.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Content can corrupt stored passwords by injecting line breaks" href="https://bugzilla.mozilla.org/show_bug.cgi?id=394610">Content can corrupt stored passwords by injecting line breaks</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0417">National Vulnerability Database (NVD) - CVE-2008-0417</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-03.html">MFSA 2008-03</a></dt>
<dd>
<h3 class="title- mg-">Privilege escalation, XSS, Remote Code Execution</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributors <strong>moz_bug_r_a4</strong> and <em>Boris Zbarsky</em> submitted a series of vulnerabilities which allow scripts from page content to escape from its sandboxed context and/or run with chrome privileges. An additional vulnerability reported by <tt class="di">moz_bug_r_a4</tt> demonstrated that the <tt class="di">XMLDocument.load()</tt> function can be used to inject script into another site, violating the browser&#8217;s same-origin policy.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="List of JavaScript privilege escalation bugs" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=386695,393761,393762,399298,407289,372075,363597">List of JavaScript privilege escalation bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0415">National Vulnerability Database (NVD) - CVE-2008-0415</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-02.html">MFSA 2008-02</a></dt>
<dd>
<h3 class="title- mg-">Multiple file input focus stealing vulnerabilities</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researchers <em>hong</em> and <em>Gregory Fleisher</em> each reported a variant on earlier reported bugs regarding focus shifting in file input controls. Their variants used file input controls nested inside <tt class="di">&lt;label&gt;</tt> tags to take advantage of automatic focus shifting into the file input field noted on the Hacker WebZine. As with the earlier reported issues this issue could be used to force a user to upload arbitrary files assuming the attacker knows the full path and name of the file.</p>
<p>These bugs are variations on earlier problems reported by <em>Charles McAuley</em> and <em>Michal Zalewski</em> which were fixed in <strong>Firefox 2.0.0.4</strong>, as well as an issue reported by hong which was fixed in <strong>Firefox 2.0.0.8</strong>.<br />
Gregory Fleisher also submitted a series of demonstrations of different ways to lure a user to place focus into the file input control manually. These demonstrations included &#8220;focus spoofing&#8221; by selectively capturing keystrokes and placing the captured characters where the user thinks the focus should be.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="List Focus shifting bugs" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=404451,408034,404391,405299">List of Focus shifting bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0414">National Vulnerability Database (NVD) - CVE-2008-0414</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-01.html">MFSA 2008-01</a></dt>
<dd>
<h3 class="title- mg-">Crashes with evidence of memory corruption (rv:1.8.1.12)</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox 2.0.0.12 and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.</p>
<p class="notice">Thunderbird shares the browser engine with Firefox and could be vulnerable if JavaScript were to be enabled in mail. This is not the default setting and we strongly discourage users from running JavaScript in mail. Without further investigation we cannot rule out the possibility that for some of these an attacker might be able to prepare memory for exploitation through some means other than JavaScript such as large images.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="JavaScript Engine Crashes" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087">List of JavaScript Engine Crashes</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0413">National Vulnerability Database (NVD) - CVE-2008-0413</a></li>
<li><a class="exturl icn-r1" title="Browser Crashes" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=398088,393141,364801,346405,396613,394337,406290">List of Browser Crashes Bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0412">National Vulnerability Database (NVD) - CVE-2008-0412</a></li>
</ul>
</div>
</dd>
</dl>
<h2 class="cb">Thunderbird Security Release</h2>
<p>Thunderbird 2.0.0.12 is schedule to be release on <a href="http://wiki.mozilla.org/Releases/Thunderbird_2.0.0.12">February 28</a>. </p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r1" href="http://www.mozilla.com/en-US/firefox/all.html">Download Firefox 2.0.0.12</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/firefox-20012-security-release/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to Setup Firefox 3 (beta) AutoComplete</title>
		<link>http://42.kaizeku.com/firefox/how-to-setup-firefox-3-beta-autocomplete/</link>
		<comments>http://42.kaizeku.com/firefox/how-to-setup-firefox-3-beta-autocomplete/#comments</comments>
		<pubDate>Sun, 06 Jan 2008 05:34:04 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[about:config hack]]></category>

		<category><![CDATA[aboutconfig]]></category>

		<category><![CDATA[ajax]]></category>

		<category><![CDATA[autocomplete]]></category>

		<category><![CDATA[firefox+hack]]></category>

		<category><![CDATA[firefox3]]></category>

		<category><![CDATA[json]]></category>

		<category><![CDATA[Tips]]></category>

		<category><![CDATA[Tutorials]]></category>

		<category><![CDATA[web+browser]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/firefox/how-to-setup-firefox-3-beta-autocomplete/</guid>
		<description><![CDATA[


Firefox 3 (beta) is amazing and much-much better than its earlier versions. But there is some minor caveat that I think is a bit annoying (In my opinion) the Autocompletion. The autocomplete max results is set to 25 by default, if there is similar results when you type in any URL in the address bar, [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p class="note mgb rr"><img src='http://gmodules.com/ig/proxy?url=http://blog.kakkoi.net/wp-content/uploads/2008/01/firefox-wordmark.png' alt='firefox3 logo wordmark' class="fl" width='79' height='100' /><br />
<a href="http://www.mozilla.com/en-US/firefox/all-beta.html" title="firefox 3 beta at mozilla.org">Firefox 3 (beta)</a> is amazing and much-much better than its earlier versions. But there is some minor caveat that I think is a bit annoying (In my opinion) the <a href="http://en.wikipedia.org/wiki/Autocompletion" title="wikipidea articles on autocomplete" class="exturl icn-r">Autocompletion</a>. The <strong class="fw-">autocomplete</strong> max results is set to 25 by default, if there is similar results when you type in any <abbr title="Uniform Resources Locator">URL</abbr> in the address bar, it will stretch down quite far (and disappeared within few seconds). </p>
<p>This is not something that I can&#8217;t live with, but it&#8217;s really straining my eyes every now and then. So here&#8217;s a quick guide on how you can manage the auto-complete results with your own preferences, complete with visual guide. </p>
<p><span id="more-137"></span></p>
<dl id="firefox-3b-autocomplete" class="profile mgt cb cf">
<dd>
<h2>Firefox About Config</h2>
<p><span class="fw">1.</span> First, open Firefox Browser type <em>about:config</em> in address bar. (optionally you may uncheck the &#8220;show this warning next time&#8221; and proceed with clicking &#8220;I&#8217;ll be careful, I promise!&#8221;. :)</dd>
<dd id="about-config">
<img width='572' height='396' src='http://blog.kakkoi.net/wp-content/uploads/2008/01/about-config.png' alt='firefox aboutconfig' />
</dd>
<dd id="firefox-advanced-preferences">
<h2>Setup Firefox Advanced Preferences</h2>
<p><span class="fw">2.</span>on <cite>about:config</cite> &#8216;filter&#8217; input bar, type in <strong>browser.urlbar.maxRichResults</strong>.
</dd>
<dd>
<img class="mgt mgb" width='451' height='189' src='http://blog.kakkoi.net/wp-content/uploads/2008/01/autocomplete-settings.png' alt='firefox autocomplete settings browser.urlbar.maxRichResults' />
</dd>
<dd>
<span class="fw">3.</span> Click on <em>browser.urlbar.maxRichResults</em>. On the <cite>Input Prompt Window</cite> type in your prefer value. For this guide I set it to 5 (recommended settings is around 5 - 10 ).
</dd>
<dd>
<img class="mgt mgb" src='http://blog.kakkoi.net/wp-content/uploads/2008/01/autocomplete-set.png' alt='set firefox autocomplete' width='476' height='298' />
</dd>
<dd class="mgt">
<span class="fw">4.</span> Result should be similar like the below example.</p>
<dd>
<img class="mgt mgb" width='460' height='210' src='http://blog.kakkoi.net/wp-content/uploads/2008/01/autocomplete-fin.png' alt='firefox Advanced Preferences browser.urlbar.maxRichResults set to 5' />
</dd>
<dd>
<span class="fw">5.</span> Finished, restart your Firefox browser and test the auto-complete.
</dd>
<dd>
<img class="mgt mgb" width='491' height='229' src='http://blog.kakkoi.net/wp-content/uploads/2008/01/autocomplete-preview.png' alt='autocomplete-preview.png' />
</dd>
</dl>
<p>Thanks for reading, merci</p>
<h2 class="cb">Related Posts</h2>
<ul class="xoxo">
<li><a class="inurl icn-r1" href="/firefox/firefox-20012-security-release/">Firefox 2.0.0.12 Urgent Security Release</a></li>
</ul>
<h2 class="cb mgb-">External Links</h2>
<ul class="xoxo exturl pdt">
<li><a rel="nofollow external" href="http://www.mozilla.org/support/firefox/tips">Mozilla Firefox Help: Tips &amp; Trick</a></li>
<li><a href="http://www.google.com/search?q=firefox3+autocomplete">Google Firefox3 Autocomplete</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/how-to-setup-firefox-3-beta-autocomplete/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firebug for Firefox 3.0b+</title>
		<link>http://42.kaizeku.com/firefox/firebug-for-firefox-30b/</link>
		<comments>http://42.kaizeku.com/firefox/firebug-for-firefox-30b/#comments</comments>
		<pubDate>Sat, 05 Jan 2008 06:54:31 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Firefox Add-ons]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[addons]]></category>

		<category><![CDATA[firebug]]></category>

		<category><![CDATA[fireclipse]]></category>

		<category><![CDATA[firefox3]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/firefox/firebug-for-firefox-30b/</guid>
		<description><![CDATA[

I really lost without Firebug. Googling around I found this Firebug 1.1.0b10. Its compatible with Firefox 3.0b1, 3.0b2, 3.0b3, 3.0b4 &#038; Latest 3.0b5 (beta 5)  . Until Joe Hewitt release Firebug 1.1 (probably for firefox 3 release) You can try this Firebug 1.1 beta, download it at fireclipse. It working hu ho.
Excerpt from fireclipse
Firebug [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/firebug-firefox-3.png' alt='firebug-firefox-3.png' width="128" height="128" class="photo thumb- fl" />I really lost without <a href="http://en.wikipedia.org/wiki/Firebug_(Firefox_extension)"><abbr title="FirefoxAddons">Firebug</abbr></a>. Googling around I found this <strong>Firebug 1.1.0b10</strong>. Its <cite>compatible</cite> with <strong class="fw-">Firefox 3.0b1, 3.0b2, 3.0b3, 3.0b4 &#038; Latest 3.0b5 (beta 5) </strong> . Until <span class="vcard"><a href="http://www.joehewitt.com/" class="url fn microformat icn-r1">Joe Hewitt</a></span> release Firebug 1.1 <cite>(probably for firefox 3 release)</cite> You can try this <strong class="fw- hilite-4">Firebug 1.1 beta</strong>, download it at <a href="http://fireclipse.xucia.com" rel="external nofollow" class="exturl icn-r1">fireclipse</a>. It working hu ho.</p>
<p class="mgb-"><small>Excerpt from fireclipse</small></p>
<blockquote class="mgt-"><p class="quote"><strong>Firebug 1.1</strong> is Firebug 1.05 by Joe Hewitt with enhancements and bug fixes by John J. Barton (IBM Almaden) and Max Stepanov (aptana)<br/><br/>The file is an XPI file that will add-on to Firefox as Firebug v1.1. Firefox&#8217;s updater will allow you to get new experimental versions until Firebug 1.1 is official. </p>
</blockquote>
<p><span id="more-130"></span></p>
<h3 class="cb mgt mgb-">Download</h3>
<ul class="xoxo exturl pdt">
<li><a href="http://getfirebug.com/releases/">Firebug Release Archive</a></li>
</ul>
<h5 class="cb mgt mgb-">Related Posts</h5>
<ul class="xoxo exturl">
<li><a class="inturl" title="Firefox 2.0.0.12 Urgent Security Release" href="/firefox/firefox-20012-security-release/">Firefox 2.0.0.12 Urgent Security Release</a></li>
</ul>
<h3 class="cb mgt mgb-">External Links</h3>
<ul class="xoxo exturl">
<li><a title="Firebug 1.10b Overview" href="http://fireclipse.xucia.com/page/Fireclipse_Overview">Firebug 1.10b Overview</a></li>
<li><a href="http://www.getfirebug.com/">Official Firebug</a></li>
<li><a href="http://groups.google.com/group/firebug">Firebug Google Group</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/firebug-for-firefox-30b/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Block Apple Quicktime ActiveX &#038; RTSP Exploit</title>
		<link>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/</link>
		<comments>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 17:45:50 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Apple]]></category>

		<category><![CDATA[QuickTime]]></category>

		<category><![CDATA[mac]]></category>

		<category><![CDATA[buffer+overflow]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[ie6]]></category>

		<category><![CDATA[ie7]]></category>

		<category><![CDATA[internet+explorer]]></category>

		<category><![CDATA[jikto]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[RSTP]]></category>

		<category><![CDATA[safari]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/</guid>
		<description><![CDATA[<p><img width="128" height="128" style="float: left;" alt="Fixes Apple QuickTime" src="http://i.kakkoi.net/leopard/QuickTimePlayer.png" longdesc="http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/" title="Quicktime Logo" /><strong style="font-weight:400">Apple QuickTime</strong> contains a stack <a href="http://en.wikipedia.org/wiki/Buffer_overflow" rev="wikipedia:Buffer_overflow" title="buffer overflow" rel="external nofollow">buffer overflow</a> vulnerability in the way it handles the <abbr title="Real Time Streaming Protocol ">RTSP</abbr> Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocol</p><strong>Live Example</strong>
<ul class="xoxo nfo">
<li><a href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/">GNUcitizen- Backdooring QuickTime Movies </a></li>
<li><a href="http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html">Apple QuickTime redirection to the RTSP exploit</a></li>

</ul>
Elia Florio (Symantec) wrap  a good introduction post regarding <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">QuickTime 0 day Exploit</a>. 


<h2 style="border-top:1px solid #ccc; margin-top:38px;padding-top:14px">Known Vulnerabilities Proof of concept (milw0rm).</h2>
<ul class="xoxo nfo">
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY3Mw.curie,80,302">Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit </a> </li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY2NA.curie,80,302">Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 &#38; 7</a></li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1Nw.curie,80,302">Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)</a></li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1MQ.curie,80,302">Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit</a></li>
</ul>

<h2 style="margin-top:18px;padding-top:14px">Workarounds</h2>
You may try the following workarounds [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://i.kakkoi.net/leopard/QuickTimePlayer.png" style="float: left" alt="Fixes Apple QuickTime" longdesc="http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/" title="Quicktime Logo" height="128" width="128" /><strong style="font-weight: 400">Apple QuickTime</strong> contains a stack <a href="http://en.wikipedia.org/wiki/Buffer_overflow" rev="wikipedia:Buffer_overflow" title="buffer overflow" rel="external nofollow">buffer overflow</a> vulnerability in the way it handles the <abbr title="Real Time Streaming Protocol ">RTSP</abbr> Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocol</p>
<p><strong>Live Example</strong></p>
<ul class="xoxo nfo">
<li><a href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/">GNUcitizen- Backdooring QuickTime Movies </a></li>
<li><a href="http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html">Apple QuickTime redirection to the RTSP exploit</a></li>
</ul>
<p>Elia Florio (Symantec) wrap a good introduction post regarding <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">QuickTime 0 day Exploit</a>.<br />
<span id="more-62"></span></p>
<h2 style="border-top: 1px solid #cccccc; margin-top: 38px; padding-top: 14px">Known Vulnerabilities Proof of concept (milw0rm).</h2>
<ul class="xoxo nfo">
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY3Mw.curie,80,302" rel="nofollow">Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit </a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY2NA.curie,80,302" rel="nofollow">Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 &amp; 7</a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1Nw.curie,80,302" rel="nofollow">Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)</a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1MQ.curie,80,302" rel="nofollow">Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit</a></li>
</ul>
<h2 style="margin-top: 18px; padding-top: 14px">Workarounds</h2>
<p>You may try the following workarounds, as there is no complete patch for this this vulnerability.</p>
<ul id="downloads" class="xoxo nfo">
<li> Block TCP <strong>port 554 </strong> (optionaly 7070) and UDP 6970 through 6999 in your firewall</li>
<li>Update <a href="http://www.apple.com/quicktime/download/">Quicktime</a></li>
<li> <a href="http://blog.kakkoi.net/wp-content/uploads/2007/12/disabledquicktimeactivex-kb240797.reg" title="DisabledQuicktimeActiveX-KB240797">Disabled Apple Quicktime ActiveX control running in Internet Explorer</a> (Windows registry file)</li>
<li>For Firefox - <a href="http://noscript.net/">Noscripts</a> addons</li>
</ul>
<h2 style="border-top: 1px solid #cccccc; margin-top: 38px; padding-top: 14px">Related Links</h2>
<ul class="xoxo">
<li><a href="http://info.internet.isi.edu/in-notes/rfc/files/rfc2326.txt">RTSP - rfc2326 </a> &amp; <a href="http://info.internet.isi.edu/in-notes/rfc/files/rfc1889.txt">RTP - rfc1889 </a></li>
<li><a href="http://docs.info.apple.com/article.html?artnum=307038">Apple Security Update on Safari 3 Beta Update 3.0.4</a></li>
<li><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-0252">NVD Database - Buffer overflow in Apple QuickTime</a></li>
<li><a href="http://support.microsoft.com/kb/240797">Microsoft KB240797 - How to stop an ActiveX control from running in Internet Explorer</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox Freeze While on Gmail</title>
		<link>http://42.kaizeku.com/google/firefox-freeze-while-on-gmail/</link>
		<comments>http://42.kaizeku.com/google/firefox-freeze-while-on-gmail/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 07:58:56 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Gmail]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[firefox+freezem firebug]]></category>

		<category><![CDATA[no-scriptsm]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/google/firefox-freeze-while-on-gmail/</guid>
		<description><![CDATA[<img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/gmail.gif' alt='gmail freeze'  style="margin:0pt 5px 1px 0pt;float:left"/>Recent update on Gmail has to many "Remote call" (AJAX) running (every 10secs) in the background. It will get really slow if you has a large numbers of email and spam. I'm suffering the dreaded "<strong>firefox freeze over</strong>" syndrome.

Below is a list of addons that will cause "firefox to freezeeeeeeek".  
<ul>
<li>Firebug<li>
<li> Noscripts.</li>
</ul>
Its advice to disabled both of this addons or revert gmail back to older versions. 

<small>uri code to revert gmail to older versions</small> 
<tt>http://mail.google.com/mail/?ui=1</tt>.


As gmail is getting more crappy with "overload features". I think I should start using <a rel="external" title="Thunderbird Email Client" href="www.mozilla.com/thunderbird/ " rev="mozilla:thunderbird">thunderbird</a> more often. 

p/s:  At this time of writing Google Aps Gmail is still with older version so you wont have this issue. 

]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://blog.kakkoi.net/wp-content/uploads/2007/12/gmail.gif" alt="gmail freeze" style="margin: 0pt 5px 1px 0pt; float: left" />Recent update on Gmail has to many &#8220;Remote call&#8221; (AJAX) running (every 10secs) in the background. It will get really slow if you has a large numbers of email and spam. I&#8217;m suffering the dreaded &#8220;<strong>firefox freeze over</strong>&#8221; syndrome.</p>
<p>Below is a list of addons that will cause &#8220;firefox to freezeeeeeeeee&#8221;.</p>
<ul>
<li>Firebug</li>
<li></li>
<li> Noscripts.</li>
</ul>
<p>Its advice to disabled both of this addons or revert gmail back to older versions.</p>
<p><small>uri code to revert gmail to older versions</small><br />
<tt class="di">http://mail.google.com/mail/?ui=1</tt>.</p>
<p>As gmail is getting more crappy with &#8220;overload features&#8221;. I think I should start using <a href="http://www.mozilla.com/en-US/thunderbird/" rel="external" title="Thunderbird Email Client" rev="mozilla:thunderbird">thunderbird</a> more often.</p>
<p>p/s: At this time of writing Google Aps Gmail is still with older version so you wont have this issue.</p>
<h2 class="cb">Related Posts</h2>
<ul class="xoxo">
<li><a href="/firefox/firefox-20012-security-release/">Firefox 2.0.0.12 Urgent Security Release</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/google/firefox-freeze-while-on-gmail/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
