<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Bugzilla changes</title>
	<atom:link href="http://blogs.gnome.org/ovitters/2009/09/14/bugzilla-changes/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gnome.org/ovitters/2009/09/14/bugzilla-changes/</link>
	<description>Just another GNOME Blogs weblog</description>
	<lastBuildDate>Fri, 06 Jan 2012 11:41:44 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: James Henstridge</title>
		<link>http://blogs.gnome.org/ovitters/2009/09/14/bugzilla-changes/comment-page-1/#comment-437</link>
		<dc:creator>James Henstridge</dc:creator>
		<pubDate>Wed, 16 Sep 2009 01:25:02 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/ovitters/?p=176#comment-437</guid>
		<description>I noticed that you fixed the attachments to be served from bugzilla-attachments.gnome.org.

That&#039;s a good start at closing the security hole, but it would be better to use a different domain all together.  While this change prevents attackers from reading cookies associated with bugzilla.gnome.org and scripting the site, it still lets me read and set cookies associated with &quot;*.gnome.org&quot; or &quot;gnome.org&quot;.

That leaves open an avenue for injecting cookies into other gnome.org web apps.  Depending on how they are structured, that could be used to steal sessions.</description>
		<content:encoded><![CDATA[<p>I noticed that you fixed the attachments to be served from bugzilla-attachments.gnome.org.</p>
<p>That&#8217;s a good start at closing the security hole, but it would be better to use a different domain all together.  While this change prevents attackers from reading cookies associated with bugzilla.gnome.org and scripting the site, it still lets me read and set cookies associated with &#8220;*.gnome.org&#8221; or &#8220;gnome.org&#8221;.</p>
<p>That leaves open an avenue for injecting cookies into other gnome.org web apps.  Depending on how they are structured, that could be used to steal sessions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: antimonio</title>
		<link>http://blogs.gnome.org/ovitters/2009/09/14/bugzilla-changes/comment-page-1/#comment-436</link>
		<dc:creator>antimonio</dc:creator>
		<pubDate>Mon, 14 Sep 2009 15:13:03 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/ovitters/?p=176#comment-436</guid>
		<description>Why not storing the extensions in the bugzilla.org repo in order to let bugzilla users find them more easily?</description>
		<content:encoded><![CDATA[<p>Why not storing the extensions in the bugzilla.org repo in order to let bugzilla users find them more easily?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- This Quick Cache file was built for (  blogs.gnome.org/ovitters/2009/09/14/bugzilla-changes/feed/ ) in 1.22347 seconds, on Feb 12th, 2012 at 12:51 am UTC. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on Feb 12th, 2012 at 1:51 am UTC -->
