<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en-us" xmlns="http://www.w3.org/2005/Atom"><title>Simon Willison's Weblog: michal-zalewski</title><link href="http://simonwillison.net/" rel="alternate"/><link href="http://simonwillison.net/tags/michal-zalewski.atom" rel="self"/><id>http://simonwillison.net/</id><updated>2008-07-03T14:35:25+00:00</updated><author><name>Simon Willison</name></author><entry><title>ratproxy</title><link href="https://simonwillison.net/2008/Jul/3/ratproxy/#atom-tag" rel="alternate"/><published>2008-07-03T14:35:25+00:00</published><updated>2008-07-03T14:35:25+00:00</updated><id>https://simonwillison.net/2008/Jul/3/ratproxy/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://code.google.com/p/ratproxy/"&gt;ratproxy&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
“A semi-automated, largely passive web application security audit tool”—watches you browse and highlights potential XSS, CSRF and other vulnerabilities in your application. Created by Michal Zalewski  at Google.


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/csrf"&gt;csrf&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/google"&gt;google&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/michal-zalewski"&gt;michal-zalewski&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/proxies"&gt;proxies&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/ratproxy"&gt;ratproxy&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/testing"&gt;testing&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/xss"&gt;xss&lt;/a&gt;&lt;/p&gt;



</summary><category term="csrf"/><category term="google"/><category term="michal-zalewski"/><category term="proxies"/><category term="ratproxy"/><category term="security"/><category term="testing"/><category term="xss"/></entry><entry><title>Firefox promiscuous IFRAME access bug</title><link href="https://simonwillison.net/2007/Jun/6/firefox/#atom-tag" rel="alternate"/><published>2007-06-06T10:00:21+00:00</published><updated>2007-06-06T10:00:21+00:00</updated><id>https://simonwillison.net/2007/Jun/6/firefox/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://lcamtuf.coredump.cx/ifsnatch/"&gt;Firefox promiscuous IFRAME access bug&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Lets malicious sites “display disruptive or misleading contents in the context of an attacked site” and intercept keystrokes! The demo worked in Camino 1.5 as well. Avoid using Gecko-based browsers until this is patched?


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/camino"&gt;camino&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/firefox"&gt;firefox&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/iframes"&gt;iframes&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/michal-zalewski"&gt;michal-zalewski&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;&lt;/p&gt;



</summary><category term="camino"/><category term="firefox"/><category term="iframes"/><category term="michal-zalewski"/><category term="security"/></entry><entry><title>Gaping holes exposed in fully-patched IE 7, Firefox</title><link href="https://simonwillison.net/2007/Jun/6/gaping/#atom-tag" rel="alternate"/><published>2007-06-06T09:57:55+00:00</published><updated>2007-06-06T09:57:55+00:00</updated><id>https://simonwillison.net/2007/Jun/6/gaping/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://blogs.zdnet.com/security/?p=254"&gt;Gaping holes exposed in fully-patched IE 7, Firefox&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Michal Zalewski released a new Firefox 2.0 vulnerability in addition to the IE cookie stealing one.

    &lt;p&gt;&lt;small&gt;&lt;/small&gt;Via &lt;a href="http://blog.outer-court.com/archive/2007-06-06-n84.html"&gt;blog.outer-court.com&lt;/a&gt;&lt;/small&gt;&lt;/p&gt;


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/firefox"&gt;firefox&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/internet-explorer"&gt;internet-explorer&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/michal-zalewski"&gt;michal-zalewski&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;&lt;/p&gt;



</summary><category term="firefox"/><category term="internet-explorer"/><category term="michal-zalewski"/><category term="security"/></entry></feed>