<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: 2005-07-26 Trunk builds</title>
	<atom:link href="http://www.squarefree.com/burningedge/2005/07/27/2005-07-26-trunk-builds/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.squarefree.com/burningedge/2005/07/27/2005-07-26-trunk-builds/</link>
	<description>Developments in nightly builds of Mozilla Firefox</description>
	<pubDate>Thu, 07 Aug 2008 23:28:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: Shawn</title>
		<link>http://www.squarefree.com/burningedge/2005/07/27/2005-07-26-trunk-builds/#comment-2426</link>
		<dc:creator>Shawn</dc:creator>
		<pubDate>Wed, 27 Jul 2005 14:15:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/burningedge/2005/07/27/2005-07-26-trunk-builds/#comment-2426</guid>
		<description>Jan: I'd consider that a security bug. Some webapps regularly use the referer as a sort of authentication for allowing actions to get executed. I wouldn't recommend that anyone use that method, but it gets used a lot and can easily get broken. But holes like this allow for it to get triggered by an unsuspecting user through XSS, rather than someone maliciously doing it themselves.</description>
		<content:encoded><![CDATA[<p>Jan: I&#8217;d consider that a security bug. Some webapps regularly use the referer as a sort of authentication for allowing actions to get executed. I wouldn&#8217;t recommend that anyone use that method, but it gets used a lot and can easily get broken. But holes like this allow for it to get triggered by an unsuspecting user through XSS, rather than someone maliciously doing it themselves.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jan!</title>
		<link>http://www.squarefree.com/burningedge/2005/07/27/2005-07-26-trunk-builds/#comment-2425</link>
		<dc:creator>Jan!</dc:creator>
		<pubDate>Wed, 27 Jul 2005 10:37:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/burningedge/2005/07/27/2005-07-26-trunk-builds/#comment-2425</guid>
		<description>In what way is bug 300942 ( and background: url(); send the wrong referer for the image request) a security bug? Because it allowed spoofing the referrer?</description>
		<content:encoded><![CDATA[<p>In what way is bug 300942 ( and background: url(); send the wrong referer for the image request) a security bug? Because it allowed spoofing the referrer?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
