Posts

Showing posts from September, 2008

jSmile 0.4 - Stand alone Version

nic comment: hey. thank u for that awesome plugin. how can i download the smilie package? i want to host them on my webspace because i want to be independet from other hosters. I have recently updated my jQuery plugin, called jSmile , and the biggest news is that it does not require anymore external resources. Thanks to inline uri data, the script now comes " full optionals ", or better, with base64 encoded GIFs images included. Instead of external CSS classes, images, and cross host dependencies, jSmile can now easily be integrated in every http or http s site, and without network delays. Its size is obviously bigger than before, but using a minifier and gzip compression, it fits perfectly under 7Kb . Compatibility Chrome FireFox Internet Explorer 8 Opera Safari WebKit Enjoy ;)

Internet Explorer Security Hole - A Better Example

Again, about the security hole I talked about last posts, but this time with a really simple example . How does the example work Open Internet Explorer, whatever version Go in this page Write a fake user name and a fake password, or a fake email address and a password Click Submit What does the example do Emulates user actions via javascripts with some version of IE, it could be able to grab both fields values in any case, it demonstrates you that every site could steal your compiled fields in every other site, if the autocomplete option is not forced to be disabled What could do a malicious, and hidden, code steal your data steal your email steal your credit card information (a really famous company, as example, suffers this problem, so somebody could steal credit cards details of million of people) steal your details steal your searches via common search engines etc, etc More details in my old post I wrote last Saturday , the one th

Internet Explorer 6, 7, or 8 exposes users data via JavaScript

Ok, ok, I know these are Google Chrome dedicated days , but how can be possible that my last post did not receive attention at all? Maybe with this title somebody will read more carefully what I wrote few days ago ... or maybe not, who knows? :?

Security Basis, and an Internet Explorer data stealer

It has been about 4 years, or more, that I know about this problem, but for some reason I did not talk about it, scared by possible reactions. In other words, I was waiting for some noise over the net, or some fix from Microsoft, but nothing is happening. Actually, Microsoft is working hard on Internet Explorer 8, but the problem I am talking about, is still present ... so, I suppose it is time to tell you how dangerous this IE "feature" could be, and how dangerous could be to forget a little detail in a form, like the autocomplete attribute. The magic autocomplete option Every browser tries to make our net life as simple as possible, and when we start inserting data in an input field, it suggests us a couple of words or, if the name of that field is unique enough, directly the most probable word, name, or number, we are going to insert. To perform this operation, we could start typing the name, or simply use the down arrow button to open the list of options, and choose, usu

Google Chrome Fix

Update 2008/09/04 I have created a new version that should be able to recognise the correct Google directory in every supported windows, and not only English version. Please do not hesitate to tell me if the created link for No Sandbox Option is not creating it properly, thank you. Google Chrome Fix Multi Language OS ----------------------- I successfully tested the new browser in my laptop, while today I had some headache at work. This is the reason I created in few minutes a simple Windows Application that let you choose which option you want to solve crashes during Google Chrome startup: The application failed to initialize properly (0x00000005). Press Ok to terminate application. Please note that the registry fix option changes a key that should solve Symantec problems, but it is not clear if this key could change security level for those PC that use Symantec end point protection, or similar softwares. In every other case, the GUI create a link to launch Chrome without multiple san