<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Channel 9 Forums - Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Forums/rss"></atom:link>
	<image>
		<url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url>
		<title>Channel 9 Forums - Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<link>http://channel9.msdn.com/Forums</link>
	</image>
	<description>Channel 9 keeps you up to date with the latest news and behind the scenes info from Microsoft that developers love to keep up with. From LINQ to SilverLight – Watch videos and hear about all the cool technologies coming and the people behind them.</description>
	<link>http://channel9.msdn.com/Forums</link>
	<language>en</language>
	<pubDate>Sun, 19 May 2013 04:00:10 GMT</pubDate>
	<lastBuildDate>Sun, 19 May 2013 04:00:10 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<c9:totalResults>28</c9:totalResults>
	<c9:pageCount>-28</c9:pageCount>
	<c9:pageSize>-1</c9:pageSize>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><a href="http://news.zdnet.com/2100-1009_22-6121608.html">http://news.zdnet.com/2100-1009_22-6121608.html</a><br>
<br>
<p><b>SAN DIEGO--The open-source Firefox Web browser is critically flawed in the way it handles JavaScript, two hackers said Saturday afternoon.
</b></p>
<p>An attacker could commandeer a computer running the browser simply by crafting a Web page that contains some
<a href="http://news.zdnet.com/2100-1009_22-6100019.html?tag=nl" title="FAQ: JavaScript insecurities -- Friday, Jul 28, 2006">
malicious JavaScript code</a>, Mischa Spiegelmock and Andrew Wbeelsoi said in a presentation at the
<a target="_blank" href="http://dw.com.com/redir?destUrl=http%3A%2F%2Fwww.toorcon.org%2F&amp;siteId=22&amp;oId=2100-1009-6121608&amp;ontId=1009&amp;lop=nl.ex">
ToorCon hacker conference</a> here. The flaw affects Firefox on Windows, Apple Computer's Mac OS X and Linux, they said.
</p>
<p>&quot;Internet Explorer, everybody knows, is not very secure. But Firefox is also fairly insecure,&quot; said Spiegelmock, who in everyday life works at blog company SixApart. He detailed the flaw, showing a slide that displayed key parts of the attack code needed
 to exploit it. </p>
<p>The flaw is specific to Firefox's implementation of JavaScript, a 10-year-old scripting language widely used on the Web. In particular, various programming tricks can cause a stack overflow error, Spiegelmock said. The implementation is a &quot;complete mess,&quot;
 he said. &quot;It is impossible to patch.&quot; <br>
</p>
.............<br>
<br>
The hackers claim they know of about 30 unpatched Firefox flaws. They don't plan to disclose them, instead holding on to the bugs.<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/234935#234935</link>
		<pubDate>Sun, 01 Oct 2006 21:42:28 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/234935#234935</guid>
		<dc:creator>blowdart</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/blowdart/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>blowdart wrote:</div>
<div>&#65279;&quot;Internet Explorer, everybody knows, is not very secure.&quot;</div>
</blockquote>
<br>
Ah, blanket statements. Every attention seeker's best friend.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/6d6002936e3f43b5b99f9dec0018164b#6d6002936e3f43b5b99f9dec0018164b</link>
		<pubDate>Sun, 01 Oct 2006 22:13:07 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/6d6002936e3f43b5b99f9dec0018164b#6d6002936e3f43b5b99f9dec0018164b</guid>
		<dc:creator>Sven Groot</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Sven Groot/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p>OMG... those hackers are complete idiots!<br>
<br>
&quot;The hackers claim they know of about 30 unpatched Firefox flaws. They don't plan to disclose them, instead holding on to the bugs.&quot;<br>
<br>
Mozilla's respose:<br>
<br>
&quot;I do hope you guys change your minds and decide to report the holes to us and take away $500 per vulnerability instead of using them for botnets.&quot;<br>
<br>
Hacker's response:<br>
<br>
&quot;It is a double-edged sword, but what we're doing is really for the greater good of the Internet, we're setting up communication networks for black hats.&quot;<br>
<br>
My response:<br>
<br>
30 * 500 = $15,000<br>
<br>
Those two hackers could have scored $15,000 to share amongst themselves by simply disclosing information about their findings.<br>
<br>
<br>
Regards,<br>
Vincent<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/2e2b306ee3d54504b85a9dec0018170f#2e2b306ee3d54504b85a9dec0018170f</link>
		<pubDate>Sun, 01 Oct 2006 23:04:29 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/2e2b306ee3d54504b85a9dec0018170f#2e2b306ee3d54504b85a9dec0018170f</guid>
		<dc:creator>Xaero_Vincent</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Xaero_Vincent/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p>I wonder how long until there is a flaw in the wild.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/6437e8b84382433695e29dec0018173c#6437e8b84382433695e29dec0018173c</link>
		<pubDate>Sun, 01 Oct 2006 23:07:52 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/6437e8b84382433695e29dec0018173c#6437e8b84382433695e29dec0018173c</guid>
		<dc:creator>Jason Cox</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Jason Cox/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>Xaero_Vincent wrote:</div>
<div>&quot;It is a double-edged sword,<i> but what we're doing is really for the greater good of the Internet</i>,
<b>we're setting up communication networks for black hats</b>.&quot;</div>
</blockquote>
<br>
<br>
A slight contradiction, surely?<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/d96f01107ae9450e97019dec0018176b#d96f01107ae9450e97019dec0018176b</link>
		<pubDate>Sun, 01 Oct 2006 23:10:22 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/d96f01107ae9450e97019dec0018176b#d96f01107ae9450e97019dec0018176b</guid>
		<dc:creator>W3bbo</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/W3bbo/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>W3bbo wrote:</div>
<div>&#65279;A slight contradiction, surely?</div>
</blockquote>
<br>
<br>
Indeed. They are consciously admitting to engagement in illegal activities and&nbsp; suggesting that users ought to feel privileged to be exploited by them and their affiliates.<br>
<br>
<br>
Regards,<br>
Vincent<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/7153e2df7afd496eb36d9dec0018179a#7153e2df7afd496eb36d9dec0018179a</link>
		<pubDate>Sun, 01 Oct 2006 23:38:31 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/7153e2df7afd496eb36d9dec0018179a#7153e2df7afd496eb36d9dec0018179a</guid>
		<dc:creator>Xaero_Vincent</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Xaero_Vincent/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>Xaero_Vincent wrote:</div>
<div><br>
<table>
<tbody>
<tr>
<td>&#65279;OMG... those hackers are complete idiots!</td>
</tr>
</tbody>
</table>
<br>
&lt;snip&gt;<br>
<br>
My response:<br>
<br>
30 * 500 = $15,000<br>
<br>
Those two hackers could have scored $15,000 to share amongst themselves by simply disclosing information about their findings.<br>
<br>
<br>
Regards,<br>
Vincent<br>
</div>
</blockquote>
<br>
<br>
The problem&nbsp;with your response&nbsp;that $15,000 for 30 exploits&nbsp;is basically nothing between two people. A given browser exploit for IE supposedly has a street value of $10,000. Assuming FireFox exploits are about the same in price, they make 20x by holding them
 back from MoFo.<br>
<br>
Not quite idiotic to hold them back if you have loose ethics. I doubt they have 30 exploits, but they probably take a great deal of pleasure making people with a (smug) sense of security scared again.<br>
<br>
Side note: IMO, they should be responsible and disclose them.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/ba1b9d1a05364461ab169dec001817cc#ba1b9d1a05364461ab169dec001817cc</link>
		<pubDate>Mon, 02 Oct 2006 00:16:58 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/ba1b9d1a05364461ab169dec001817cc#ba1b9d1a05364461ab169dec001817cc</guid>
		<dc:creator>petknep_home</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/petknep_home/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>Jason Cox wrote:</div>
<div>&#65279;I wonder how long until there is a flaw in the wild.</div>
</blockquote>
<br>
<br>
In the mean time simply use <a href="https://addons.mozilla.org/firefox/722/">NoScript
</a>to block JavaScript from being run on sites that you don't trust.<br>
<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/b22e05ab9844421c8db89dec00181815#b22e05ab9844421c8db89dec00181815</link>
		<pubDate>Mon, 02 Oct 2006 01:07:49 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/b22e05ab9844421c8db89dec00181815#b22e05ab9844421c8db89dec00181815</guid>
		<dc:creator>Grumpy</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Grumpy/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p>Reminds me of a story about two Security guys who found a flaw in wifi cards that can hack any OS, they even demo'd it a mac laptop.<br>
<br>
Funny they had the same sort of statement, &quot;we have found a real flaw but we don't want to tell people about it....&quot; Bull&lt;cough!&gt;<br>
<br>
Since Mozilla are looking at all the code for JavaScript to see if there is an issue then if it exists there's a god chance it will be fixed soon.<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/2c4afc0761704c0b9f969dec00181845#2c4afc0761704c0b9f969dec00181845</link>
		<pubDate>Mon, 02 Oct 2006 07:57:27 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/2c4afc0761704c0b9f969dec00181845#2c4afc0761704c0b9f969dec00181845</guid>
		<dc:creator>Another_Darren</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Another_Darren/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>blowdart wrote:</div>
<div>&#65279;<a href="http://news.zdnet.com/2100-1009_22-6121608.html">http://news.zdnet.com/2100-1009_22-6121608.html</a>
<p>The flaw is specific to Firefox's implementation of JavaScript, a 10-year-old scripting language widely used on the Web. In particular, various programming tricks can cause a stack overflow error, Spiegelmock said. The implementation is a &quot;complete mess,&quot;
 he said. &quot;It is impossible to patch.&quot; <br>
</p>
</div>
</blockquote>
<br>
<br>
Isn't this a good reason to throw out the old implementation of javascript and start with a new one, that doesn't have these flaws?
<br>
I think that would be a better idea than waiting for the hackers to use the holes for their blackhat communication framework, but that's just me <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-5.gif' alt='Wink' /><br>
<p></p></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/a7c584d6cb3c4986901c9dec0018187a#a7c584d6cb3c4986901c9dec0018187a</link>
		<pubDate>Mon, 02 Oct 2006 08:11:20 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/a7c584d6cb3c4986901c9dec0018187a#a7c584d6cb3c4986901c9dec0018187a</guid>
		<dc:creator>Willem Meints</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/WillemM/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p>When does software become impossible to patch ?</p>
<p>These sort of statements always intrigue me.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/c9037f17799c407b858b9dec001818a9#c9037f17799c407b858b9dec001818a9</link>
		<pubDate>Mon, 02 Oct 2006 08:12:47 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/c9037f17799c407b858b9dec001818a9#c9037f17799c407b858b9dec001818a9</guid>
		<dc:creator>MB</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/MB/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>WillemM wrote:</div>
<div>&#65279;<br>
Isn't this a good reason to throw out the old implementation of javascript and start with a new one, that doesn't have these flaws?
<br>
<p></p>
</div>
</blockquote>
<br>
<br>
I'd rather hear that it is impossible to patch from a FF dev rather than the hacker, given the fact they are not oblivious of the effects of over-generalisation (IE is insecure blah blah) then they may also be prone to overexageration.<br>
<br>
<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/de24113f12df4ca79af09dec001818d8#de24113f12df4ca79af09dec001818d8</link>
		<pubDate>Mon, 02 Oct 2006 09:47:05 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/de24113f12df4ca79af09dec001818d8#de24113f12df4ca79af09dec001818d8</guid>
		<dc:creator>Rossj</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Rossj/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>jaylittle wrote:</div>
<div>&#65279;
<blockquote>
<table>
<tbody>
<tr>
<td><img src="/Themes/AlmostGlass/images/icon-quote.gif"></td>
<td><strong>Another_Darren wrote:</strong> <i>&#65279;Reminds me of a story about two Security guys who found a flaw in wifi cards that can hack any OS, they even demo'd it a mac laptop.</i></td>
</tr>
</tbody>
</table>
</blockquote>
<br>
Yeah and they were pretty much totally full of it.&nbsp; The demo was done using a third party USB wireless device with a third party driver.&nbsp; Hence by default Apple had nothing to do with it since the security hole was on the driver level.</div>
</blockquote>
I'm not sure how they are full of it, didn't they&nbsp;state the above in the video <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-7.gif' alt='Perplexed' /></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/b6300db9c10044bb94a89dec00181909#b6300db9c10044bb94a89dec00181909</link>
		<pubDate>Mon, 02 Oct 2006 14:56:45 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/b6300db9c10044bb94a89dec00181909#b6300db9c10044bb94a89dec00181909</guid>
		<dc:creator>Jonathan Merriweather</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Cyonix/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p>On the plus side that fact that they refused to give Apple any information, even though claiming it was also possible with the Airport drivers, forced Apple to do a security audit and found two other issues <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif' alt='Smiley' /><br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/10bb3c3883704efcaa549dec00181938#10bb3c3883704efcaa549dec00181938</link>
		<pubDate>Mon, 02 Oct 2006 15:14:07 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/10bb3c3883704efcaa549dec00181938#10bb3c3883704efcaa549dec00181938</guid>
		<dc:creator>Rossj</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Rossj/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p>Sanctimonious bull-crap!<br>
<br>
Credibility -1<br>
<br>
Report the bugs for the good of the community, don't muck about. <br>
<br>
I hate all this &quot;I'm not going to tell you because I've got some power over you&quot;.<br>
<br>
Black Hats? Who are they ... peers? Criminals? Bank-manager? Granny? I smell a rat.<br>
<br>
I'm annoyed now, ones things for sure it won't stop me from using Firefox, but it doesn't make me feel comfortable about using it either.
<br>
<br>
Give me&nbsp;the hackers&nbsp;address, time to tell them exactly what I think of them!<br>
<br>
If only they lived in London ... I would knock on there doors, I really would! <br>
<br>
<br>
<br>
<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/0659dc1f12c448bd81729dec00181968#0659dc1f12c448bd81729dec00181968</link>
		<pubDate>Mon, 02 Oct 2006 15:57:01 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/0659dc1f12c448bd81729dec00181968#0659dc1f12c448bd81729dec00181968</guid>
		<dc:creator>David Oliver</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Sabot/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>petknep_home wrote:</div>
<div><br>
Side note: IMO, they should be responsible and disclose them.</div>
</blockquote>
<br>
<br>
Especially when a company that you work for is disclosed in the article<br>
<br>
&quot;who in everyday life works at blog company SixApart&quot;</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/a3f31bd210d94d3098dd9dec00181996#a3f31bd210d94d3098dd9dec00181996</link>
		<pubDate>Mon, 02 Oct 2006 15:58:37 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/a3f31bd210d94d3098dd9dec00181996#a3f31bd210d94d3098dd9dec00181996</guid>
		<dc:creator>Cybermagellan</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Cybermagellan/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>Cybermagellan wrote:</div>
<div>&#65279;
<blockquote>
<table>
<tbody>
<tr>
<td><img src="/Themes/AlmostGlass/images/icon-quote.gif"></td>
<td><strong>petknep_home wrote:</strong> <i><br>
Side note: IMO, they should be responsible and disclose them.</i></td>
</tr>
</tbody>
</table>
</blockquote>
<br>
<br>
Especially when a company that you work for is disclosed in the article<br>
<br>
&quot;who in everyday life works at blog company <a href="http://www.sixapart.com/">SixApart</a>&quot;</div>
</blockquote>
<br>
<br>
I bet their website is getting bombarded. Lots of free advertising?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/77d9e0a17a57407eb5619dec001819c5#77d9e0a17a57407eb5619dec001819c5</link>
		<pubDate>Mon, 02 Oct 2006 16:02:29 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/77d9e0a17a57407eb5619dec001819c5#77d9e0a17a57407eb5619dec001819c5</guid>
		<dc:creator>phreaks</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/phreaks/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p>Well looks like the black hatters don't have long to brag about their big find in FF.<br>
<br>
<a href="http://forums.mozillazine.org/viewtopic.php?t=469982">http&#58;&#47;&#47;forums.mozillazine.org&#47;viewtopic.php&#63;t&#61;469982</a><br>
<br>
Some JS bug fixes in and a new bug raised over the claims;<br>
<br>
<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=355069">https&#58;&#47;&#47;bugzilla.mozilla.org&#47;show_bug.cgi&#63;id&#61;355069</a><br>
<br>
Shows they have managed to recreate the flaw.<br>
<br>
I personally think if you found such a serious flaw and planned to use to for gain (personal network for black hatters for example) then you wouldn't brag about it!&nbsp; I think it's a personal PR stunt.<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/6f6bddc8f33c436da4db9dec001819f5#6f6bddc8f33c436da4db9dec001819f5</link>
		<pubDate>Mon, 02 Oct 2006 19:49:33 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/6f6bddc8f33c436da4db9dec001819f5#6f6bddc8f33c436da4db9dec001819f5</guid>
		<dc:creator>Another_Darren</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Another_Darren/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>petknep_home wrote:</div>
<div>&#65279;<br>
The problem&nbsp;with your response&nbsp;that $15,000 for 30 exploits&nbsp;is basically nothing between two people. A given browser exploit for IE supposedly has a street value of $10,000. Assuming FireFox exploits are about the same in price, they make 20x by holding them
 back from MoFo.</div>
</blockquote>
<br>
Not to mention that they have jobs. Well at least Mischa Spiegelmock does. Maybe he will change his mind after Six Apart fires him. I can't imagine any business trusting a company that knowingly employs&nbsp; blackhat hackers.
<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/80d04963d70b4fa6a51c9dec00181a24#80d04963d70b4fa6a51c9dec00181a24</link>
		<pubDate>Mon, 02 Oct 2006 21:35:41 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/80d04963d70b4fa6a51c9dec00181a24#80d04963d70b4fa6a51c9dec00181a24</guid>
		<dc:creator>Oberon</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Oberon/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p>Apparently this is a <a href="http://arstechnica.com/news.ars/post/20061003-7885.html">
hoax</a>. I hate to think how much dev time this might have wasted, and can imagine how upset a corporate might be if someone pulled this one and they wasted hours or days looking for a bug that was already known about.<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/1ae34ae319564a9e9e779dec00181a54#1ae34ae319564a9e9e779dec00181a54</link>
		<pubDate>Tue, 03 Oct 2006 17:43:52 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/1ae34ae319564a9e9e779dec00181a54#1ae34ae319564a9e9e779dec00181a54</guid>
		<dc:creator>Rossj</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Rossj/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>Rossj wrote:</div>
<div>&#65279;Apparently this is a <a href="http://arstechnica.com/news.ars/post/20061003-7885.html">
hoax</a>. I hate to think how much dev time this might have wasted, and can imagine how upset a corporate might be if someone pulled this one and they wasted hours or days looking for a bug that was already known about.<br>
</div>
</blockquote>
<br>
<br>
Hoax or not, it doesn't mean that the implementation of JavaScript in FF is not almost impossible to patch.<br>
<br>
Rotem</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/dfacbb4032f046bfb1d99dec00181a84#dfacbb4032f046bfb1d99dec00181a84</link>
		<pubDate>Tue, 03 Oct 2006 18:12:21 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/dfacbb4032f046bfb1d99dec00181a84#dfacbb4032f046bfb1d99dec00181a84</guid>
		<dc:creator>Rotem Kirshenbaum</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Rotem Kirshenbaum/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>Rotem Kirshenbaum wrote:</div>
<div>&#65279;
<blockquote>
<table>
<tbody>
<tr>
<td><img src="/Themes/AlmostGlass/images/icon-quote.gif"></td>
<td><strong>Rossj wrote:</strong><i>&#65279;Apparently this is a <a href="http://arstechnica.com/news.ars/post/20061003-7885.html">
hoax</a>. I hate to think how much dev time this might have wasted, and can imagine how upset a corporate might be if someone pulled this one and they wasted hours or days looking for a bug that was already known about.<br>
</i></td>
</tr>
</tbody>
</table>
</blockquote>
<br>
<br>
Hoax or not, it doesn't mean that the implementation of JavaScript in FF is not almost impossible to patch.<br>
<br>
Rotem</div>
</blockquote>
<br>
<br>
I think the fact that the FF devs have already 'patched' the problem proves otherwise <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-5.gif' alt='Wink' /><br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/aafcab7ccc8f42b3b50a9dec00181ab5#aafcab7ccc8f42b3b50a9dec00181ab5</link>
		<pubDate>Tue, 03 Oct 2006 18:16:11 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/aafcab7ccc8f42b3b50a9dec00181ab5#aafcab7ccc8f42b3b50a9dec00181ab5</guid>
		<dc:creator>Rossj</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Rossj/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>Rotem Kirshenbaum wrote:</div>
<div>&#65279;
<blockquote>
<table>
<tbody>
<tr>
<td><img src="/Themes/AlmostGlass/images/icon-quote.gif"></td>
<td><strong>Rossj wrote:</strong><i>&#65279;Apparently this is a <a href="http://arstechnica.com/news.ars/post/20061003-7885.html">
hoax</a>. I hate to think how much dev time this might have wasted, and can imagine how upset a corporate might be if someone pulled this one and they wasted hours or days looking for a bug that was already known about.<br>
</i></td>
</tr>
</tbody>
</table>
</blockquote>
<br>
<br>
Hoax or not, it doesn't mean that the implementation of JavaScript in FF is not almost impossible to patch<a></a>.<br>
<br>
Rotem</div>
</blockquote>
<br>
<br>
Wow, you laid it out with all the facts...&nbsp; &quot;doesn't mean&quot;, &quot;not almost&quot;<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/66a93d04a0ee4cd18a279dec00181ae5#66a93d04a0ee4cd18a279dec00181ae5</link>
		<pubDate>Tue, 03 Oct 2006 18:27:44 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/66a93d04a0ee4cd18a279dec00181ae5#66a93d04a0ee4cd18a279dec00181ae5</guid>
		<dc:creator>Another_Darren</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Another_Darren/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>Another_Darren wrote:</div>
<div>&#65279;
<blockquote>
<table>
<tbody>
<tr>
<td><img src="/Themes/AlmostGlass/images/icon-quote.gif"></td>
<td><strong>Rotem Kirshenbaum wrote:</strong> <i>&#65279;
<blockquote>
<table>
<tbody>
<tr>
<td><img src="/Themes/AlmostGlass/images/icon-quote.gif"></td>
<td><strong>Rossj wrote:</strong> <i>&#65279;Apparently this is a <a href="http://arstechnica.com/news.ars/post/20061003-7885.html">
hoax</a>. I hate to think how much dev time this might have wasted, and can imagine how upset a corporate might be if someone pulled this one and they wasted hours or days looking for a bug that was already known about.<br>
</i></td>
</tr>
</tbody>
</table>
</blockquote>
<br>
<br>
Hoax or not, it doesn't mean that the implementation of JavaScript in FF is not almost impossible to patch<a></a>.<br>
<br>
Rotem</i></td>
</tr>
</tbody>
</table>
</blockquote>
<br>
<br>
Wow, you laid it out with all the facts...&nbsp; &quot;doesn't mean&quot;, &quot;not almost&quot;<br>
</div>
</blockquote>
<br>
<br>
I'm not saying that it's a fact. <br>
Let me explain: &quot;A is true and B is true&quot;. Just because A isn't true doesn't mean the B is false also <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif' alt='Smiley' /><br>
<br>
Heck, I don't know if the JS implementation in Mozilla is a mess&nbsp;or not. If t's really a 10-year old code, than it probably is. Or maybe it's not (tautology rocks ! <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-4.gif' alt='Tongue Out' /> ).<br>
<br>
Rotem</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/2c081efe8427450385f49dec00181b18#2c081efe8427450385f49dec00181b18</link>
		<pubDate>Tue, 03 Oct 2006 19:43:44 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/2c081efe8427450385f49dec00181b18#2c081efe8427450385f49dec00181b18</guid>
		<dc:creator>Rotem Kirshenbaum</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Rotem Kirshenbaum/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><a href="http://developer.mozilla.org/devnews/index.php/2006/10/02/update-possible-vulnerability-reported-at-toorcon/">Here we go.<br>
</a><br>
<blockquote>
<div>Alleged hacker wrote:</div>
<div><br>
The main purpose of our talk was to be humorous.<br>
...<br>
I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly haven’t used it to take over anyone else’s computer and execute arbitrary code.<br>
</div>
</blockquote>
<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/114236c053b24cea9fcf9dec00181b48#114236c053b24cea9fcf9dec00181b48</link>
		<pubDate>Tue, 03 Oct 2006 20:40:28 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/114236c053b24cea9fcf9dec00181b48#114236c053b24cea9fcf9dec00181b48</guid>
		<dc:creator>Rossj</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Rossj/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>Rossj wrote:</div>
<div>&#65279;<a href="http://developer.mozilla.org/devnews/index.php/2006/10/02/update-possible-vulnerability-reported-at-toorcon/">Here we go.<br>
</a><br>
<blockquote>
<table>
<tbody>
<tr>
<td><img src="/Themes/AlmostGlass/images/icon-quote.gif"></td>
<td><strong>Alleged hacker wrote:</strong><i><br>
The main purpose of our talk was to be humorous.<br>
...<br>
I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly haven’t used it to take over anyone else’s computer and execute arbitrary code.<br>
</i></td>
</tr>
</tbody>
</table>
</blockquote>
<br>
</div>
</blockquote>
<br>
What's everybody upset about? It was all a joke. &lt;insert eye rolling icon here&gt;<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/839a165391664143abb69dec00181b78#839a165391664143abb69dec00181b78</link>
		<pubDate>Tue, 03 Oct 2006 21:01:20 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/839a165391664143abb69dec00181b78#839a165391664143abb69dec00181b78</guid>
		<dc:creator>Oberon</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Oberon/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p>Ya, I am being larfing so much I am being making wetting of the pants.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/1a1b1b31c9d64ea1925d9dec00181ba6#1a1b1b31c9d64ea1925d9dec00181ba6</link>
		<pubDate>Wed, 04 Oct 2006 03:15:18 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/1a1b1b31c9d64ea1925d9dec00181ba6#1a1b1b31c9d64ea1925d9dec00181ba6</guid>
		<dc:creator>MB</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/MB/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Firefox vunerability &amp;quot;impossible to patch&amp;quot;</title>
		<description><![CDATA[<p><blockquote>
<div>MB wrote:</div>
<div>&#65279;Ya, I am being larfing so much I am being making wetting of the pants.</div>
</blockquote>
<br>
<br>
?<br>
<br>
Larfing?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/4b7a57806e994b3cbe609dec00181bd5#4b7a57806e994b3cbe609dec00181bd5</link>
		<pubDate>Wed, 04 Oct 2006 03:19:12 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/234935-Firefox-vunerability-quotimpossible-to-patchquot/4b7a57806e994b3cbe609dec00181bd5#4b7a57806e994b3cbe609dec00181bd5</guid>
		<dc:creator>JonathonW</dc:creator>
		<slash:comments>28</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/CannotResolveSymbol/Discussions/RSS</wfw:commentRss>
	</item>
</channel>
</rss>