Search the web
Sign In
New User? Sign Up
caplet · The Caplet Group
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 243 - 272 of 309   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
243
... I'm kind of late to this (just joined this group) but this just seems like a losing battle. Trusting that a host hasn't opened themselves up to an attack...
marcel.laverdet
Offline Send Email
Sep 5, 2008
1:07 pm
244
Of course the attack assumes that the host uses Prototype and also has an iframe on the page, but I imagine such cases aren't hard to find. There's also...
Kris Zyp
kriszyp
Online Now Send Email
Sep 8, 2008
4:08 pm
245
... the prototypes (of course this could simply be documented to be unsafe)? Also, the mozilla() fix function replaces value in existing slots, it doesn't seem...
marcel.laverdet
Offline Send Email
Sep 8, 2008
4:35 pm
246
... Understood. I think the situation may be a little different for me than for the ADsafe in general, since I am focused on a Dojo-specific impl of ADsafe....
Kris Zyp
kriszyp
Online Now Send Email
Sep 8, 2008
4:48 pm
247
... has an iframe on the ... several other ways you can ... vectors? I see you're ... that approach won't work ... I looked at the Mozilla array methods, and...
Douglas Crockford
douglascrock...
Offline Send Email
Sep 8, 2008
5:04 pm
248
... If there is an iframe somewhere on the page, they can leak access to it (I was able to reproduce that). Kris ... From: Douglas Crockford To:...
Kris Zyp
kriszyp
Online Now Send Email
Sep 8, 2008
5:07 pm
249
... Thanks, Marcel, that was really helpful. ADsafe's mozilla function is now conditioned on the existence of slots for concat, filter, map, reverse, slice,...
Douglas Crockford
douglascrock...
Offline Send Email
Sep 8, 2008
6:51 pm
250
... As follows: <iframe src="#"></iframe> <script> var leak; ([].forEach || 0)(function(a,b,win) { leak = win; }); leak.alert(leak); </script> Simple demo: ...
marcel.laverdet
Offline Send Email
Sep 8, 2008
6:58 pm
251
... These vulnerabilities were first pointed out by Jeff Walden and Eli Friedman, then interns at Mozilla, in August 2007. Jeff wrote back then in reply to...
brendaneich
Offline Send Email
Sep 8, 2008
7:24 pm
252
... Thanks. ADsafe is now wrapping concat every filter forEach map reduce reduceRight reverse slice some sort....
Douglas Crockford
douglascrock...
Offline Send Email
Sep 8, 2008
8:06 pm
253
There is another ADsafe demonstration widget at http://adsafe.org/sudoku.html...
Douglas Crockford
douglascrock...
Offline Send Email
Oct 8, 2008
5:18 pm
254
... Doesn't seem to work correctly in Chrome (for example, no play button). -- http://www.apache-ssl.org/ben.html http://www.links.org/ "There is no...
Ben Laurie
benlaurie2000
Online Now Send Email
Oct 8, 2008
5:49 pm
255
Works for me in Chrome. -- Alan Karp...
Alan Karp
alanhkarp
Offline Send Email
Oct 8, 2008
9:59 pm
256
... Seems to work on Safari. Cheers - Bill ... Bill Frantz |"We used to quip that "password" is the most common 408-356-8506 | password. Now it's...
Bill Frantz
frantz@...
Send Email
Oct 8, 2008
11:31 pm
257
... Hmm. On second attempt it worked for me, too. Odd. -- http://www.apache-ssl.org/ben.html http://www.links.org/ "There is no limit to what a man...
Ben Laurie
benlaurie2000
Online Now Send Email
Oct 9, 2008
8:41 am
258
I've noticed that Chrome gets addled if it's been open for many days. This morning mine lost its ability to talk to the network, but I've seen other symptoms....
Alan Karp
alanhkarp
Offline Send Email
Oct 9, 2008
3:15 pm
259
I implemented PPK's focus hack (http://www.quirksmode.org/blog/archives/2008/04/delegating_the.html) in ADsafe, so focus and blur events may now be delegated....
Douglas Crockford
douglascrock...
Offline Send Email
Oct 23, 2008
6:02 pm
260
Live Labs has released a public preview of their Javascript sandbox. http://websandbox.livelabs.com/ See the clock sample: ...
marcel.laverdet
Offline Send Email
Oct 25, 2008
12:41 am
261
The EcmaScript 3.1 draft standard is rapidly congealing towards an official standard. The Kona version at < ...
Mark S. Miller
erights@...
Send Email
Nov 6, 2008
10:34 pm
262
I added another sample page. This one shows two simple widgets that coexist. http://adsafe.org/roman.html...
Douglas Crockford
douglascrock...
Offline Send Email
Jan 3, 2009
4:59 pm
263
The w3c Technical Architecture Group (TAG) discuss ocaps for the web starting at http://www.w3.org/2001/tag/2008/12/10-minutes#item03 teaser sample: 'DO: SW...
Mark Miller
capsecure
Offline Send Email
Jan 5, 2009
9:14 pm
264
... For me, the highlight was, "Crockford says add a switch in Firefox to disable non-adSafe ads". If this feature gets adopted, and used, we'll see an...
Bill Frantz
frantz@...
Send Email
Jan 5, 2009
10:35 pm
265
At the end of the minutes, it looks like the TAG is casting about for a next step. One useful step would be to consider amending the web-arch document's...
Tyler Close
tjclose
Offline Send Email
Jan 6, 2009
12:17 am
266
http://apps.yahoo.com/-yNmsEV4q/ I'm "ocap capo". It (and therefore Caja) also work on an iPhone. Thanks to the Yahoo! and Zynga folks! -- Cheers, --MarkM...
Mark S. Miller
erights@...
Send Email
Jan 6, 2009
2:35 am
267
This is announcement of the call for papers for the third in a series of successful workshops on topics related to security and privacy for Web 2.0. This...
Larry Koved
larrykoved
Offline Send Email
Jan 18, 2009
2:38 am
268
At http://wiki.ecmascript.org/doku.php?id=ses:ses_proposal_working_draft is posted a very rough first draft for a "Secure ECMAScript" standard, derived from...
Mark Miller
capsecure
Offline Send Email
Jan 20, 2009
6:15 pm
269
... Hash: SHA1 Do you have an overview of the differences between SES and ES3.1 (or maybe it is easier to define the differences between SES and Cajita)? I see...
Kris Zyp
kriszyp
Online Now Send Email
Jan 21, 2009
3:10 pm
270
... Three synergies between ES3.1 strict and SES: * Better target: Easy to translate SES to ES3.1-strict * Better source: Easier to translate ES3.1-strict to...
Mark S. Miller
erights@...
Send Email
Jan 25, 2009
6:55 am
271
Consider the following JavaScript source: [ /[/]/ /foo]/ + bar According to the ES3 spec, this is interpreted as: [ new RegExp("[") ] / new RegExp("foo]") +...
David-Sarah Hopwood
david.hopwood@...
Send Email
Feb 9, 2009
5:16 pm
272
From what I remember this started out as a bug in IE and then Firefox followed suit for compatibility which left the other browsers with no choice. I can't...
Marcel Laverdet
marcel.laverdet
Offline Send Email
Feb 9, 2009
5:43 pm
Messages 243 - 272 of 309   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help