Search the web
Sign In
New User? Sign Up
caplet · The Caplet Group
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want to share photos of your group with the world? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 137 - 166 of 309   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
137
http://www.crockford.com/html/ "<module> creates a sub-tree which can contain a document with a communication channel. See http://json.org/module.html for a ...
robertsayre2000
Offline Send Email
Jan 11, 2008
1:43 am
138
I have added an optional adsafe parameter to the JSLINT(source, option, adsafe) function. It is an object whose keys are global variable names and values are...
Douglas Crockford
douglascrock...
Online Now Send Email
Jan 30, 2008
1:55 am
139
... From: Mike Samuel <mikesamuel@...> Date: Jan 29, 2008 8:15 PM Subject: [Caja] secure string interpolation in javascript To: Google Caja Discuss...
Mark Miller
capsecure
Offline Send Email
Jan 30, 2008
5:07 am
140
I am on the program committee of the second workshop on Web 2.0 Security and Privacy (http://seclab.cs.rice.edu/w2sp/2008/cfp.html). It will be held the day...
Douglas Crockford
douglascrock...
Online Now Send Email
Jan 30, 2008
3:16 pm
141
... Very nice. I like the context scanning mechanism. I'll be curious to see what the fsm.txt looks like for SQL. It wasn't clear to me how the interpolator...
Monty Zukowski
monty_zukowski
Offline Send Email
Jan 30, 2008
9:21 pm
142
... Escapers can use the runtime type of the substitution values. If the SQL escaper sees an array, then it iterates over elements, and if it sees a Date, it...
Mike Samuel
mikesamuel
Offline Send Email
Jan 30, 2008
9:50 pm
143
Seems like a good idea. As a user, I'd rather see the SQL problem solved right by having a parser that's more sophisticated than a finite state machine than to...
Freeman, Tim
timothy_free...
Offline Send Email
Jan 30, 2008
10:28 pm
144
... Fair enough. It's tough to implement sophisticated and efficient parsers in javascript, but I'm sure that it's worthwhile in some contexts. Perhaps if...
Mike Samuel
mikesamuel
Offline Send Email
Jan 30, 2008
10:42 pm
145
... ... Now that ANTLR 3 has a retargetable backend, this might be a good motivation to get a JavaScript backend implemented. ActionScript, perl, Python &...
Monty Zukowski
monty_zukowski
Offline Send Email
Feb 1, 2008
3:50 pm
146
I updated JSLint today in a step to bring more truth to this expression: JSON < ADsafe < Cajita < Caja < ES3 < Proposed ES4 ADsafe now allows all strings as...
Douglas Crockford
douglascrock...
Online Now Send Email
Feb 19, 2008
9:03 pm
147
I relaxed the ADsafe.get(object, name) function. The only names it excludes now are the _hanging_underbar_ names. It allows all other names. It requires that...
Douglas Crockford
douglascrock...
Online Now Send Email
Feb 20, 2008
11:38 pm
148
I have been thinking about capabilities-based security and ES subsets like ADsafe and Caja, and was thinking about another subset that is intriguing to me and...
Kris Zyp
kriszyp
Online Now Send Email
Feb 27, 2008
9:02 pm
149
I am the co-chair of the second workshop on Web 2.0 Security and Privacy (http://seclab.cs.rice.edu/w2sp/2008/cfp.html). It will be held the day after the IEEE...
Larry Koved
larrykoved
Offline Send Email
Mar 5, 2008
3:13 am
150
Doug/ADsafe people, Has there been any efforts to produce a lightweight minimal-sized ADsafe validator? With the coming browser capabilities in Cross-site XHR...
Kris Zyp
kriszyp
Online Now Send Email
Mar 17, 2008
1:40 am
151
... ADsafe validator? With the coming browser capabilities in Cross-site XHR (MS's XDR and W3C/AC proposal) and the new postMessage API, it seems there will be...
Douglas Crockford
douglascrock...
Online Now Send Email
Mar 17, 2008
1:11 pm
152
Results of a quick experiment: Pulling stuff out of JSLint.js that is not needed for ADsafe validation of JavaScript produced an adsafe.js file that is 34K. I...
Douglas Crockford
douglascrock...
Online Now Send Email
Mar 17, 2008
5:05 pm
153
... A validator for a Javascript subset like ADsafe does have to check for syntactic validity, because: - it cannot trust the browser's eval to accept only...
David-Sarah Hopwood
david.hopwood@...
Send Email
Mar 17, 2008
5:05 pm
154
Here is my attempt at an ADsafe validator: http://www.persvr.org/test/capability-validate.html Let me know if anyone can find any false acceptances (scripts...
Kris Zyp
kriszyp
Online Now Send Email
Mar 18, 2008
8:19 pm
155
... get successfully eval'ed that are unsafe). ... presume that it is also a lot faster since it is using simpler regex-based checking rather than full AST...
Douglas Crockford
douglascrock...
Online Now Send Email
Mar 20, 2008
1:57 pm
156
... Yes, regular expression based validation does seem impropable. However, it seems like you could also make an argument that it easier to reason about and...
Kris Zyp
kriszyp
Online Now Send Email
Mar 20, 2008
2:50 pm
157
... Do we have a regression test suite of tricky examples? For instance, I don't see the string "cc_on" in Kris' validator, but that feature tripped up ADsafe...
Adam Barth
hk9565
Offline Send Email
Mar 20, 2008
6:35 pm
158
... That would be awesome. ... Thanks for the heads, fixed it. Thanks, Kris...
Kris Zyp
kriszyp
Online Now Send Email
Mar 21, 2008
7:21 pm
159
... Can you disallow @ outside of string literals entirely? What if ADSafe code is included in a container that has @cc_on, and does an @set that overrides a...
Mike Samuel
mikesamuel
Offline Send Email
Mar 21, 2008
7:40 pm
160
... '@' does not appear anywhere in the ES3 grammar outside string literals, regexp literals, and comments, right? Isn't ADsafe defined to be a subset of ES3? ...
David-Sarah Hopwood
david.hopwood@...
Send Email
Mar 21, 2008
11:09 pm
161
On 21/03/2008, David-Sarah Hopwood ... Yep. @ often appears in JSDoc style comments: http://jsdoc.sourceforge.net/#tagref so banning @ in comments might make...
Mike Samuel
mikesamuel
Offline Send Email
Mar 22, 2008
12:05 am
162
... Certainly seems reasonable to insist that containers don't do the eval inside a @cc_on. Kris...
Kris Zyp
kriszyp
Online Now Send Email
Mar 22, 2008
3:02 am
163
... I meant my point a bit more generally: Assume that any extension to strict ES3 is designed by an evil genius trying to break ADsafe (or Caja, or whatever),...
David-Sarah Hopwood
david.hopwood@...
Send Email
Mar 22, 2008
3:04 am
164
On 21/03/2008, David-Sarah Hopwood ... Or a committee of evil geniuses. ... Caja deals with many of these problems by rewriting. We can deal perfectly well...
Mike Samuel
mikesamuel
Offline Send Email
Mar 22, 2008
3:20 am
165
... Also, because with the new cross-site XHR and XDR capabilities, web sites can directly request the scripts from other sites, which can potentially be...
Kris Zyp
kriszyp
Online Now Send Email
Mar 22, 2008
3:35 am
166
Is there any documentation available on the specific attacks that the various rules in ADsafe are protecting against? Most of the rules are pretty obvious, but...
Kris Zyp
kriszyp
Online Now Send Email
Apr 4, 2008
7:50 pm
Messages 137 - 166 of 309   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help