<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Pwning Opera Unite with Inferno&#8217;s Eleven</title>
	<atom:link href="http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/feed/" rel="self" type="application/rss+xml" />
	<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/</link>
	<description>Inferno&#039;s Blog on Application Security</description>
	<lastBuildDate>Fri, 02 Apr 2010 17:28:55 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: lotha</title>
		<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/comment-page-1/#comment-273</link>
		<dc:creator>lotha</dc:creator>
		<pubDate>Sun, 08 Nov 2009 17:07:04 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=783#comment-273</guid>
		<description>Thanks for your anwser</description>
		<content:encoded><![CDATA[<p>Thanks for your anwser</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/comment-page-1/#comment-270</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Sat, 07 Nov 2009 22:28:23 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=783#comment-270</guid>
		<description>@Lotha, yes if you are running the Unite Server, it is very important to run it in a sanboxie kind of env with a good firewall. that will reduce down the risk to a great extent as application boundaries are not crossed and less chances of code execution.</description>
		<content:encoded><![CDATA[<p>@Lotha, yes if you are running the Unite Server, it is very important to run it in a sanboxie kind of env with a good firewall. that will reduce down the risk to a great extent as application boundaries are not crossed and less chances of code execution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lotha</title>
		<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/comment-page-1/#comment-269</link>
		<dc:creator>lotha</dc:creator>
		<pubDate>Sat, 07 Nov 2009 22:22:59 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=783#comment-269</guid>
		<description>Thanks for your answer, but I&#039;m afraid they don&#039;t intend to change it, as  they say it &quot;feature by design&quot;.
On the other hand, it&#039;s normal when you run a server that your ip and port are made visible, but I don&#039;t understand why it has to be in the source.
So. Do you think it reduces the risk if Unite is runned into sandboxie and with a firewall ? Even if the ip and port are visible ?</description>
		<content:encoded><![CDATA[<p>Thanks for your answer, but I&#8217;m afraid they don&#8217;t intend to change it, as  they say it &#8220;feature by design&#8221;.<br />
On the other hand, it&#8217;s normal when you run a server that your ip and port are made visible, but I don&#8217;t understand why it has to be in the source.<br />
So. Do you think it reduces the risk if Unite is runned into sandboxie and with a firewall ? Even if the ip and port are visible ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/comment-page-1/#comment-268</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Sat, 07 Nov 2009 20:58:38 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=783#comment-268</guid>
		<description>@Lotha - Vulnerability 3 is just about information disclosure. An attacker might be able to further exploit the service since he knows the exact server ip and port no. This might be fixed before the Opera Unite production version is launched.</description>
		<content:encoded><![CDATA[<p>@Lotha &#8211; Vulnerability 3 is just about information disclosure. An attacker might be able to further exploit the service since he knows the exact server ip and port no. This might be fixed before the Opera Unite production version is launched.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lotha</title>
		<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/comment-page-1/#comment-266</link>
		<dc:creator>Lotha</dc:creator>
		<pubDate>Sat, 07 Nov 2009 20:03:30 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=783#comment-266</guid>
		<description>Thanks for this article.
What can be done with vulnerability 3 ? Is it possible to access the whole host-computer by scanning port 8840 ?</description>
		<content:encoded><![CDATA[<p>Thanks for this article.<br />
What can be done with vulnerability 3 ? Is it possible to access the whole host-computer by scanning port 8840 ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inferno</title>
		<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/comment-page-1/#comment-260</link>
		<dc:creator>Inferno</dc:creator>
		<pubDate>Thu, 29 Oct 2009 18:57:32 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=783#comment-260</guid>
		<description>@Mark - give it a try to see how many things remain. i dont currently have the time to try it again :). However, i can give you the feedback provided to me by Opera Security Team.
6,7,8,9,11 are planned to be fixed.
4,10 are known limitations that they plan to address in future.
1,2,3,5 are features by design.</description>
		<content:encoded><![CDATA[<p>@Mark &#8211; give it a try to see how many things remain. i dont currently have the time to try it again <img src='http://securethoughts.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . However, i can give you the feedback provided to me by Opera Security Team.<br />
6,7,8,9,11 are planned to be fixed.<br />
4,10 are known limitations that they plan to address in future.<br />
1,2,3,5 are features by design.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/comment-page-1/#comment-259</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Thu, 29 Oct 2009 18:38:28 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=783#comment-259</guid>
		<description>Worth pointing out the build that they tried is over 100 builds out of date.

I&#039;d like to see how many of these things still remain in the latest:

http://snapshot.opera.com/windows/Opera_1010_1848_in.exe</description>
		<content:encoded><![CDATA[<p>Worth pointing out the build that they tried is over 100 builds out of date.</p>
<p>I&#8217;d like to see how many of these things still remain in the latest:</p>
<p><a href="http://snapshot.opera.com/windows/Opera_1010_1848_in.exe" rel="nofollow">http://snapshot.opera.com/windows/Opera_1010_1848_in.exe</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Upquark</title>
		<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/comment-page-1/#comment-235</link>
		<dc:creator>Upquark</dc:creator>
		<pubDate>Sun, 13 Sep 2009 21:22:41 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=783#comment-235</guid>
		<description>Very cool! And a nice read as well. Well done!</description>
		<content:encoded><![CDATA[<p>Very cool! And a nice read as well. Well done!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MaXe</title>
		<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/comment-page-1/#comment-233</link>
		<dc:creator>MaXe</dc:creator>
		<pubDate>Mon, 07 Sep 2009 08:31:57 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=783#comment-233</guid>
		<description>Very nice work indeed, I&#039;ll post it to my website giving you credit of course :-)</description>
		<content:encoded><![CDATA[<p>Very nice work indeed, I&#8217;ll post it to my website giving you credit of course <img src='http://securethoughts.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: N3mes1s &#187; Blog Archive &#187; Opera Unite: pwning</title>
		<link>http://securethoughts.com/2009/08/pwning-opera-unite-with-infernos-eleven/comment-page-1/#comment-230</link>
		<dc:creator>N3mes1s &#187; Blog Archive &#187; Opera Unite: pwning</dc:creator>
		<pubDate>Thu, 03 Sep 2009 08:36:43 +0000</pubDate>
		<guid isPermaLink="false">http://securethoughts.com/?p=783#comment-230</guid>
		<description>[...] Pwning Opera Unite with Inferno’s Eleven [...]</description>
		<content:encoded><![CDATA[<p>[...] Pwning Opera Unite with Inferno’s Eleven [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

