Search the web
Sign In
New User? Sign Up
caplet · The Caplet Group
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 223 - 253 of 309   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
223
The first edition of adsafe.js is available at http://adsafe.org/adsafe.js. It still lacks dom wrappage and interwidget communication....
Douglas Crockford
douglascrock...
Offline Send Email
Jun 3, 2008
8:40 pm
224
... Attached is a rough first draft of a safe DOM wrapper. The main idea is that untrusted script views DOM nodes simply as integer handles. To read or mutate...
Adam Barth
hk9565
Offline Send Email
Jun 6, 2008
9:18 am
225
... It would be easy to make the handles opaque: var nodes = []; function handleToNode(handle) { return handle.__node__; } function nodeToHandle(node) { if...
David-Sarah Hopwood
david.hopwood@...
Send Email
Jun 7, 2008
2:43 am
226
... I was slightly unclear here. Encapsulation of the underlying DOM node objects from the script is required; in the implementation I suggested, that is...
David-Sarah Hopwood
david.hopwood@...
Send Email
Jun 7, 2008
2:57 am
227
... [...] ... [...] ... This will leak memory on IE (even after the nodes array has become unreferenced after leaving the page), because JScript's excuse for a...
David-Sarah Hopwood
david.hopwood@...
Send Email
Jun 7, 2008
11:14 pm
228
I have been investigating an idea for a secure cross-site transport. It seems unlikely that no one has done anything like this before, but I can't find any...
Kris Zyp
kriszyp
Online Now Send Email
Jun 9, 2008
5:32 pm
229
Recently I have been working on a new project, dojox.secure, to add a secure mechanism to Dojo for loading and executing untrusted code and widgets, and I...
Kris Zyp
kriszyp
Online Now Send Email
Jun 9, 2008
6:34 pm
230
I am developing an Ajax library for ADsafe. It applies a capability discipline to the dom tree, blocking access to parents and siblings. It wraps collections...
Douglas Crockford
douglascrock...
Offline Send Email
Jun 9, 2008
8:12 pm
231
I created a safe option in JSLint for checking the safe subset. The adsafe option assumes the safe option, and additionally checks for ADsafe widget...
Douglas Crockford
douglascrock...
Offline Send Email
Jun 21, 2008
11:33 pm
232
On Fri, Jun 27, 2008 at 1:44 AM, Mario Heiderich ... Wow. No, we had no idea. I admit that I am shocked that the one tight encapsulation mechanism in...
Mark S. Miller
erights@...
Send Email
Jun 27, 2008
4:03 pm
233
... Hi Brendan, I was completely unaware of this history and did indeed think that this was a newly opened hole. I'm very pleased to find that it isn't. I'm...
Mark S. Miller
erights@...
Send Email
Jun 27, 2008
8:50 pm
234
... I reply-all'ed since Mark cc'ed me, but I was not a member of the caplet@yahoogroups.com list so the message bounced off that address. Here's the...
brendaneich
Offline Send Email
Jun 27, 2008
9:09 pm
235
I added setExpression to the banned method list....
Douglas Crockford
douglascrock...
Offline Send Email
Jul 16, 2008
10:11 pm
236
Is that the javascript equivalent of IE's expression(...) CSS extension? If so, I'm confused. If code is getting access to a raw HTMLElement or style object,...
Mike Samuel
mikesamuel
Offline Send Email
Jul 16, 2008
11:09 pm
237
... string to ... You're right. Never mind....
Douglas Crockford
douglascrock...
Offline Send Email
Jul 16, 2008
11:25 pm
238
... This is a Microsoft DOM method <http://msdn.microsoft.com/en-us/library/ms531196(VS.85).aspx> <http://www.webreference.com/js/tips/000719.html>. It's...
David-Sarah Hopwood
david.hopwood@...
Send Email
Jul 17, 2008
3:30 pm
239
A sample ADsafe widget can be seen at http://www.adsafe.org/bats.html It plays the game of Bats....
Douglas Crockford
douglascrock...
Offline Send Email
Aug 12, 2008
2:04 pm
240
Not directly object-capability news, but very good news from an ocap perspective. ... From: Brendan Eich <brendan@...> Date: Wed, Aug 13, 2008 at 2:26...
Mark S. Miller
erights@...
Send Email
Aug 13, 2008
9:43 pm
241
ADsafe will now accept subscripting expressions that use the + prefix, so koda[bosonda] can be written as koda[+bosonda] instead of as ADSAFE.get(koda,...
Douglas Crockford
douglascrock...
Offline Send Email
Aug 31, 2008
12:39 am
243
... I'm kind of late to this (just joined this group) but this just seems like a losing battle. Trusting that a host hasn't opened themselves up to an attack...
marcel.laverdet
Offline Send Email
Sep 5, 2008
1:07 pm
244
Of course the attack assumes that the host uses Prototype and also has an iframe on the page, but I imagine such cases aren't hard to find. There's also...
Kris Zyp
kriszyp
Online Now Send Email
Sep 8, 2008
4:08 pm
245
... the prototypes (of course this could simply be documented to be unsafe)? Also, the mozilla() fix function replaces value in existing slots, it doesn't seem...
marcel.laverdet
Offline Send Email
Sep 8, 2008
4:35 pm
246
... Understood. I think the situation may be a little different for me than for the ADsafe in general, since I am focused on a Dojo-specific impl of ADsafe....
Kris Zyp
kriszyp
Online Now Send Email
Sep 8, 2008
4:48 pm
247
... has an iframe on the ... several other ways you can ... vectors? I see you're ... that approach won't work ... I looked at the Mozilla array methods, and...
Douglas Crockford
douglascrock...
Offline Send Email
Sep 8, 2008
5:04 pm
248
... If there is an iframe somewhere on the page, they can leak access to it (I was able to reproduce that). Kris ... From: Douglas Crockford To:...
Kris Zyp
kriszyp
Online Now Send Email
Sep 8, 2008
5:07 pm
249
... Thanks, Marcel, that was really helpful. ADsafe's mozilla function is now conditioned on the existence of slots for concat, filter, map, reverse, slice,...
Douglas Crockford
douglascrock...
Offline Send Email
Sep 8, 2008
6:51 pm
250
... As follows: <iframe src="#"></iframe> <script> var leak; ([].forEach || 0)(function(a,b,win) { leak = win; }); leak.alert(leak); </script> Simple demo: ...
marcel.laverdet
Offline Send Email
Sep 8, 2008
6:58 pm
251
... These vulnerabilities were first pointed out by Jeff Walden and Eli Friedman, then interns at Mozilla, in August 2007. Jeff wrote back then in reply to...
brendaneich
Offline Send Email
Sep 8, 2008
7:24 pm
252
... Thanks. ADsafe is now wrapping concat every filter forEach map reduce reduceRight reverse slice some sort....
Douglas Crockford
douglascrock...
Offline Send Email
Sep 8, 2008
8:06 pm
253
There is another ADsafe demonstration widget at http://adsafe.org/sudoku.html...
Douglas Crockford
douglascrock...
Offline Send Email
Oct 8, 2008
5:18 pm
Messages 223 - 253 of 309   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help