<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: טכניקת פישינג חדשה - New phishing technique</title>
	<atom:link href="http://firefang.net/blog/850/feed" rel="self" type="application/rss+xml" />
	<link>http://firefang.net/blog/850</link>
	<description>May your sockets never timeout</description>
	<pubDate>Fri, 21 Nov 2008 12:02:38 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: סשה</title>
		<link>http://firefang.net/blog/850#comment-6760</link>
		<dc:creator>סשה</dc:creator>
		<pubDate>Sat, 05 Apr 2008 14:41:54 +0000</pubDate>
		<guid isPermaLink="false">http://firefang.net/blog/850#comment-6760</guid>
		<description>Does web forgery detection work as a browser plugin? Why can't it warn before or disable submitting forms from local HTML to remote servers? True, the *current* anti-phishing schemes won't work against it, but the scammers are always 0 or more steps ahead, almost by definition.</description>
		<content:encoded><![CDATA[<p>Does web forgery detection work as a browser plugin? Why can&#8217;t it warn before or disable submitting forms from local HTML to remote servers? True, the *current* anti-phishing schemes won&#8217;t work against it, but the scammers are always 0 or more steps ahead, almost by definition.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: עמרי</title>
		<link>http://firefang.net/blog/850#comment-6759</link>
		<dc:creator>עמרי</dc:creator>
		<pubDate>Sat, 05 Apr 2008 07:25:35 +0000</pubDate>
		<guid isPermaLink="false">http://firefang.net/blog/850#comment-6759</guid>
		<description>You can prevent it if with an AV, but not all users have an AV.
I was referring to web forgery detection, which does not work in this situation.</description>
		<content:encoded><![CDATA[<p>You can prevent it if with an AV, but not all users have an AV.<br />
I was referring to web forgery detection, which does not work in this situation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: סשה</title>
		<link>http://firefang.net/blog/850#comment-6757</link>
		<dc:creator>סשה</dc:creator>
		<pubDate>Sat, 05 Apr 2008 05:12:08 +0000</pubDate>
		<guid isPermaLink="false">http://firefang.net/blog/850#comment-6757</guid>
		<description>Why can't you prevent the user from opening a local HTML file (by filtering out HTML attachments)? Local HTML files get additional security priveleges (or at least are in a differente "security zone" in IE) and should be treated by any attachment-scanning software as a security risk. There is even no problem to just strip out submittable forms and Javascript from the HTML.</description>
		<content:encoded><![CDATA[<p>Why can&#8217;t you prevent the user from opening a local HTML file (by filtering out HTML attachments)? Local HTML files get additional security priveleges (or at least are in a differente &#8220;security zone&#8221; in IE) and should be treated by any attachment-scanning software as a security risk. There is even no problem to just strip out submittable forms and Javascript from the HTML.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
