<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: XSS Vulnerability in Internet Explorer HTML Attachment Download</title>
	<atom:link href="http://www.awgh.org/archives/57/feed" rel="self" type="application/rss+xml" />
	<link>http://www.awgh.org/archives/57</link>
	<description>Shaking Your Tree</description>
	<lastBuildDate>Wed, 23 Nov 2011 06:47:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Stephen</title>
		<link>http://www.awgh.org/archives/57/comment-page-1#comment-6722</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Mon, 27 Jun 2011 18:36:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.awgh.org/?p=57#comment-6722</guid>
		<description>I don&#039;t know why you say &quot;Now IE8 behaves like Firefox&quot;.  Your example page still shows the problem in Internet Explorer 8 when I test it.

It&#039;s fixed in IE9, though.  IE9 behaves like Firefox.

For IE8, the &quot;noopen&quot; header is needed for MOST files, not just HTML, due to IE&#039;s mime-type sniffing algorithm.  Serving a file as application/octet-stream?  Need to disallow &quot;Open&quot; because it may get sniffed as HTML!

And &quot;nosniff&quot; doesn&#039;t seem to have any effect in combination with with &quot;attachment&quot;.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t know why you say &#8220;Now IE8 behaves like Firefox&#8221;.  Your example page still shows the problem in Internet Explorer 8 when I test it.</p>
<p>It&#8217;s fixed in IE9, though.  IE9 behaves like Firefox.</p>
<p>For IE8, the &#8220;noopen&#8221; header is needed for MOST files, not just HTML, due to IE&#8217;s mime-type sniffing algorithm.  Serving a file as application/octet-stream?  Need to disallow &#8220;Open&#8221; because it may get sniffed as HTML!</p>
<p>And &#8220;nosniff&#8221; doesn&#8217;t seem to have any effect in combination with with &#8220;attachment&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HackTalk</title>
		<link>http://www.awgh.org/archives/57/comment-page-1#comment-5714</link>
		<dc:creator>HackTalk</dc:creator>
		<pubDate>Mon, 02 Aug 2010 20:40:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.awgh.org/?p=57#comment-5714</guid>
		<description>&lt;strong&gt;Shell of the Future v0.9.0.2 Released...&lt;/strong&gt;

This was a really good post I mentioned it on my blog...</description>
		<content:encoded><![CDATA[<p><strong>Shell of the Future v0.9.0.2 Released&#8230;</strong></p>
<p>This was a really good post I mentioned it on my blog&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Minh</title>
		<link>http://www.awgh.org/archives/57/comment-page-1#comment-3196</link>
		<dc:creator>Minh</dc:creator>
		<pubDate>Thu, 16 Jul 2009 19:43:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.awgh.org/?p=57#comment-3196</guid>
		<description>Yeah,

I totally agree - firefox handles this far better.

Do you know of any way of handling this issue for older versions of IE 6 &amp; 7?</description>
		<content:encoded><![CDATA[<p>Yeah,</p>
<p>I totally agree &#8211; firefox handles this far better.</p>
<p>Do you know of any way of handling this issue for older versions of IE 6 &amp; 7?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: basic
Database Caching 4/19 queries in 0.045 seconds using disk: basic
Object Caching 242/259 objects using disk: basic

Served from: www.awgh.org @ 2012-02-05 19:02:46 -->
