<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Phishing with URL Obfuscation continues in Safari 4</title>
	<atom:link href="http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/feed/" rel="self" type="application/rss+xml" />
	<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/</link>
	<description>Inferno&#039;s Blog on Application Security</description>
	<lastBuildDate>Thu, 17 Dec 2009 00:27:19 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Hijacking Safari 4 Top Sites with Phish Bombs &#124; SecureThoughts.com</title>
		<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/comment-page-1/#comment-202</link>
		<dc:creator>Hijacking Safari 4 Top Sites with Phish Bombs &#124; SecureThoughts.com</dc:creator>
		<pubDate>Tue, 11 Aug 2009 23:48:52 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=500#comment-202</guid>
		<description>[...] by the Safari&#8217;s inadequate protection against URL obfuscation attacks as highlighted in [3], which makes it almost impossible for a regular user to spot the fake site and differentiate it [...]</description>
		<content:encoded><![CDATA[<p>[...] by the Safari&#8217;s inadequate protection against URL obfuscation attacks as highlighted in [3], which makes it almost impossible for a regular user to spot the fake site and differentiate it [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/comment-page-1/#comment-200</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Tue, 28 Jul 2009 01:44:47 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=500#comment-200</guid>
		<description>Hi Kurt,

I had a chat with Google Security Team before i decided to write this post. They felt that their mitigation mechanisms were sufficient enough. I still kinda disagree and feel that a more uniform solution is required across all browsers, rather than each browser having one or other type of flaw.

Regards,
Inferno</description>
		<content:encoded><![CDATA[<p>Hi Kurt,</p>
<p>I had a chat with Google Security Team before i decided to write this post. They felt that their mitigation mechanisms were sufficient enough. I still kinda disagree and feel that a more uniform solution is required across all browsers, rather than each browser having one or other type of flaw.</p>
<p>Regards,<br />
Inferno</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kurt</title>
		<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/comment-page-1/#comment-199</link>
		<dc:creator>Kurt</dc:creator>
		<pubDate>Tue, 28 Jul 2009 01:26:29 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=500#comment-199</guid>
		<description>Inferno,
while your description of the chrome browsers response to this exploit is accurate, I believe, from my experience, users do not glance up at the address bar often enough to prevent falling for this. I believe Firefox&#039;s response with an error box and default selection of &quot;no&quot; is far more effective than Google&#039;s chrome. I also agree that Microsoft&#039;s response is insufficient. But even that is better than taking you directly to the link where you&#039;re asked for login credentials as what happens with chrome.
Respectfully,
Kurt</description>
		<content:encoded><![CDATA[<p>Inferno,<br />
while your description of the chrome browsers response to this exploit is accurate, I believe, from my experience, users do not glance up at the address bar often enough to prevent falling for this. I believe Firefox&#8217;s response with an error box and default selection of &#8220;no&#8221; is far more effective than Google&#8217;s chrome. I also agree that Microsoft&#8217;s response is insufficient. But even that is better than taking you directly to the link where you&#8217;re asked for login credentials as what happens with chrome.<br />
Respectfully,<br />
Kurt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: G@rFieLd</title>
		<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/comment-page-1/#comment-181</link>
		<dc:creator>G@rFieLd</dc:creator>
		<pubDate>Tue, 21 Jul 2009 09:59:38 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=500#comment-181</guid>
		<description>By the way, the KDE browser konqueror loads the URL unfortunatly too.</description>
		<content:encoded><![CDATA[<p>By the way, the KDE browser konqueror loads the URL unfortunatly too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/comment-page-1/#comment-106</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Fri, 19 Jun 2009 08:36:17 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=500#comment-106</guid>
		<description>Thanks David ! Fixed it. For Apple, hope they fix that one fast so that i can discuss it here.</description>
		<content:encoded><![CDATA[<p>Thanks David ! Fixed it. For Apple, hope they fix that one fast so that i can discuss it here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/comment-page-1/#comment-105</link>
		<dc:creator>David</dc:creator>
		<pubDate>Fri, 19 Jun 2009 07:53:39 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=500#comment-105</guid>
		<description>Inferno, I was talking about the Internet Explorer link to Microsoft on second line first paragraph. :-)

I&#039;m curious about the one you are solving with Apple.</description>
		<content:encoded><![CDATA[<p>Inferno, I was talking about the Internet Explorer link to Microsoft on second line first paragraph. <img src='http://securethoughts.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>I&#8217;m curious about the one you are solving with Apple.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/comment-page-1/#comment-92</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Thu, 18 Jun 2009 00:32:32 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=500#comment-92</guid>
		<description>Hi David, 

Thanks a lot for pointing this out. Google Analyticator messed it up, so I am now using a textarea instead. 

I reported two exploits to Apple Security Team, one of them was this one. On this issue, Apple didn&#039;t respond to me despite my repeated emails. It is pretty aweful to leave such exploits open when everyone else fixed it years ago :). On the other exploit, Apple is actively replying to my emails and I will discuss that once it is fixed. That is much more serious that this one.....</description>
		<content:encoded><![CDATA[<p>Hi David, </p>
<p>Thanks a lot for pointing this out. Google Analyticator messed it up, so I am now using a textarea instead. </p>
<p>I reported two exploits to Apple Security Team, one of them was this one. On this issue, Apple didn&#8217;t respond to me despite my repeated emails. It is pretty aweful to leave such exploits open when everyone else fixed it years ago <img src='http://securethoughts.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . On the other exploit, Apple is actively replying to my emails and I will discuss that once it is fixed. That is much more serious that this one&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Safari 4 still open to Phishing with URL Obfuscation &#124; David Sopas</title>
		<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/comment-page-1/#comment-91</link>
		<dc:creator>Safari 4 still open to Phishing with URL Obfuscation &#124; David Sopas</dc:creator>
		<pubDate>Wed, 17 Jun 2009 18:48:29 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=500#comment-91</guid>
		<description>[...] reading on SecureThoughts about the new Safari 4 on how it&#8217;s still open to phishing with URL [...]</description>
		<content:encoded><![CDATA[<p>[...] reading on SecureThoughts about the new Safari 4 on how it&#8217;s still open to phishing with URL [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/comment-page-1/#comment-90</link>
		<dc:creator>David</dc:creator>
		<pubDate>Wed, 17 Jun 2009 18:44:29 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=500#comment-90</guid>
		<description>By the way, your link to Internet Explorer is messed up :-)</description>
		<content:encoded><![CDATA[<p>By the way, your link to Internet Explorer is messed up <img src='http://securethoughts.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://securethoughts.com/2009/06/phishing-with-url-obfuscation-continues-in-safari-4/comment-page-1/#comment-89</link>
		<dc:creator>David</dc:creator>
		<pubDate>Wed, 17 Jun 2009 18:39:36 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=500#comment-89</guid>
		<description>Apple each day is proving to me that they need to open their eyes to security. 
They are &quot;ignoring&quot; or taking to much time to secure big open bugs.

The bigger they some, the less they care about security, right?</description>
		<content:encoded><![CDATA[<p>Apple each day is proving to me that they need to open their eyes to security.<br />
They are &#8220;ignoring&#8221; or taking to much time to secure big open bugs.</p>
<p>The bigger they some, the less they care about security, right?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
