<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: lolcatting all the way to the bank</title>
	<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank/</link>
	<description>Comments on MetaFilter post lolcatting all the way to the bank</description>
	<pubDate>Fri, 01 Aug 2008 13:15:52 -0800</pubDate>
	<lastBuildDate>Fri, 01 Aug 2008 13:15:52 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>lolcatting all the way to the bank</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank</link>	
		<description>&lt;a href="http://www.infoworld.com/article/08/08/01/A_photo_that_can_steal_your_online_credentials_1.html"&gt;goatse hijacked my bank account&lt;/a&gt; </description>
		<guid isPermaLink="false">post:www.metafilter.com,2008:site.73771</guid>
		<pubDate>Fri, 01 Aug 2008 13:11:34 -0800</pubDate>
		<dc:creator>quonsar</dc:creator>		<category>GIFAR</category>		<category>browser</category>		<category>exploit</category>		<category>java</category>		<category>applet</category>		<category>batshitinsane</category>		<category>hax0rz</category>		<category>lolxats</category>		<category>goatse</category>
	</item>	<item>
		<title>By: uncleozzy</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205122</link>	
		<description>&lt;a href=&quot;http://en.wikipedia.org/wiki/Jafar_(Aladdin)&quot;&gt;GIFAR&lt;/a&gt;?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205122</guid>
		<pubDate>Fri, 01 Aug 2008 13:15:52 -0800</pubDate>
		<dc:creator>uncleozzy</dc:creator>
	</item>	<item>
		<title>By: Shepherd</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205124</link>	
		<description>...and that is why I use Firefox and NoScript.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205124</guid>
		<pubDate>Fri, 01 Aug 2008 13:17:22 -0800</pubDate>
		<dc:creator>Shepherd</dc:creator>
	</item>	<item>
		<title>By: public</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205131</link>	
		<description>Not entirely sure why this has broken again today it first came out &lt;a href=&quot;http://radar.oreilly.com/2008/06/partial-same-origin-bypass-wit.html&quot;&gt;a month ago.&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205131</guid>
		<pubDate>Fri, 01 Aug 2008 13:19:22 -0800</pubDate>
		<dc:creator>public</dc:creator>
	</item>	<item>
		<title>By: roll truck roll</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205132</link>	
		<description>For stupid people, can someone please explain why this hack would only work on Facebook-type sites? Why wouldn&apos;t such an image be able to be displayed on any site?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205132</guid>
		<pubDate>Fri, 01 Aug 2008 13:20:03 -0800</pubDate>
		<dc:creator>roll truck roll</dc:creator>
	</item>	<item>
		<title>By: mr_crash_davis</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205135</link>	
		<description>&lt;i&gt;&quot;There is one catch, however. The victim would have to be logged into the Web site that is hosting the image for the attack to work. &apos;The attack is going to work best wherever you leave yourself logged in for long periods of time,&apos; Heasman said.&quot;&lt;/i&gt;

Bastards! They&apos;ve obviously developed this attack with Metafilter in mind!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205135</guid>
		<pubDate>Fri, 01 Aug 2008 13:21:21 -0800</pubDate>
		<dc:creator>mr_crash_davis</dc:creator>
	</item>	<item>
		<title>By: Debaser626</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205136</link>	
		<description>&lt;i&gt;He and his fellow Black Hat presenters have entitled their talk The Internet is Broken. 
&lt;/i&gt;

So fix it. Oh wait, you can&apos;t. 

So it&apos;s not so much broken, as it&apos;s flawed. To a certain degree, like having a window in your house is a &quot;flaw.&quot; Sure, it makes it look pretty, adds some functionality in resale, but &quot;they&quot; can use it to get in. Soooo.... you make a stronger window, &quot;they&quot; get a better crowbar, add a security system, &quot;they&quot; find the callbox, and on and on.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205136</guid>
		<pubDate>Fri, 01 Aug 2008 13:21:29 -0800</pubDate>
		<dc:creator>Debaser626</dc:creator>
	</item>	<item>
		<title>By: Ambrosia Voyeur</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205138</link>	
		<description>&lt;em&gt;goatse hijacked my bank account&lt;/em&gt;, murdered my parents and drove my husband and children to leave me. All for the *snif* lulz.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205138</guid>
		<pubDate>Fri, 01 Aug 2008 13:23:31 -0800</pubDate>
		<dc:creator>Ambrosia Voyeur</dc:creator>
	</item>	<item>
		<title>By: Debaser626</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205141</link>	
		<description>&lt;i&gt;For stupid people, can someone please explain why this hack would only work on Facebook-type sites? Why wouldn&apos;t such an image be able to be displayed on any site?&lt;/i&gt; I think they said the the image would have to be user-uploaded, so the site would have to allow for image uploads.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205141</guid>
		<pubDate>Fri, 01 Aug 2008 13:24:37 -0800</pubDate>
		<dc:creator>Debaser626</dc:creator>
	</item>	<item>
		<title>By: xorry</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205144</link>	
		<description>I&apos;m not following that link..</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205144</guid>
		<pubDate>Fri, 01 Aug 2008 13:28:07 -0800</pubDate>
		<dc:creator>xorry</dc:creator>
	</item>	<item>
		<title>By: ardgedee</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205146</link>	
		<description>&lt;a href=&quot;http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205141&quot; title=&quot;Debaser626&quot;&gt;&amp;gt;&lt;/a&gt; &lt;i&gt;can someone please explain why this hack would only work on Facebook-type sites?&lt;/i&gt;

It probably works on any website the attacker can upload an image to. A profile on Facebook is more likely to be visited by random people than a page on a brand-new website somewhere. The author of the writeup is partly trying to grab attention by namedropping, and partially illuminating a real consequence of how people currently use the web.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205146</guid>
		<pubDate>Fri, 01 Aug 2008 13:29:07 -0800</pubDate>
		<dc:creator>ardgedee</dc:creator>
	</item>	<item>
		<title>By: mark242</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205150</link>	
		<description>The fix for this is (probably) to have your Java runtime actually look at the MIME type being sent by the webserver, and refuse to actually execute code that wasn&apos;t application/x-java-archive.  The alternative (making every webserver verify the magic number of the file versus the extension and mime type) is probably too big of a problem to fix.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205150</guid>
		<pubDate>Fri, 01 Aug 2008 13:30:16 -0800</pubDate>
		<dc:creator>mark242</dc:creator>
	</item>	<item>
		<title>By: cavalier</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205151</link>	
		<description>I like that the security blog memed it as &quot;lolcat stole your [bank account, etc]&quot; yet here we&apos;ve memed it as goatse.    Someone could write a paper on that.

Neat idea -- shoving java into a GIF onto an unsuspecting web page that is already processing java.    Pisser that those social websites need so much java to do their fancypants things.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205151</guid>
		<pubDate>Fri, 01 Aug 2008 13:30:40 -0800</pubDate>
		<dc:creator>cavalier</dc:creator>
	</item>	<item>
		<title>By: Mister_A</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205153</link>	
		<description>Gross!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205153</guid>
		<pubDate>Fri, 01 Aug 2008 13:31:49 -0800</pubDate>
		<dc:creator>Mister_A</dc:creator>
	</item>	<item>
		<title>By: boo_radley</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205162</link>	
		<description>that&apos;s not the only thing goatse is jacking

&lt;strong&gt;[&lt;/strong&gt;&lt;small&gt;&lt;em&gt;UNF UNF UNF UNF&lt;/em&gt;&lt;/small&gt;&lt;strong&gt;]&lt;/strong&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205162</guid>
		<pubDate>Fri, 01 Aug 2008 13:35:34 -0800</pubDate>
		<dc:creator>boo_radley</dc:creator>
	</item>	<item>
		<title>By: mrgrimm</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205163</link>	
		<description>Seconding the &lt;a href=&quot;https://addons.mozilla.org/en-US/firefox/addon/722&quot;&gt;NoScript extension&lt;/a&gt;. I&apos;m not as confident as Shepherd that it solves the problem entirely, but why not use it.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205163</guid>
		<pubDate>Fri, 01 Aug 2008 13:35:34 -0800</pubDate>
		<dc:creator>mrgrimm</dc:creator>
	</item>	<item>
		<title>By: uncleozzy</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205164</link>	
		<description>&lt;i&gt;shoving java into a GIF onto an unsuspecting web page that is already processing java. Pisser that those social websites need so much java to do their fancypants things.&lt;/i&gt;

I think you might be confusing Java and JavaScript.  The hook here is that you&apos;re just using the social whatnot site to host the image/JAR and draw people into the trap, not that it has anything to do with executing the malicious code.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205164</guid>
		<pubDate>Fri, 01 Aug 2008 13:35:56 -0800</pubDate>
		<dc:creator>uncleozzy</dc:creator>
	</item>	<item>
		<title>By: porn in the woods</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205171</link>	
		<description>Nonsense. I&apos;ve been surfing 4chan all morning on an unpatched XP box and nothZxfti23  45X4

&lt;small&gt;[NO CARRIER]&lt;/small&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205171</guid>
		<pubDate>Fri, 01 Aug 2008 13:40:15 -0800</pubDate>
		<dc:creator>porn in the woods</dc:creator>
	</item>	<item>
		<title>By: cavalier</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205173</link>	
		<description>Wouldn&apos;t be the first time.  But my impression from the article was that the web page would have to say &quot;Hey!  There&apos;s Java on this here page,  kick up your JVM&quot;,  and that I would then attempt to compile the GIFAR and run it.    Do I have that backwards?  Never said I was a developer... foo...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205173</guid>
		<pubDate>Fri, 01 Aug 2008 13:40:36 -0800</pubDate>
		<dc:creator>cavalier</dc:creator>
	</item>	<item>
		<title>By: cortex</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205176</link>	
		<description>Do we call this steganaggrophy?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205176</guid>
		<pubDate>Fri, 01 Aug 2008 13:42:31 -0800</pubDate>
		<dc:creator>cortex</dc:creator>
	</item>	<item>
		<title>By: saulgoodman</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205177</link>	
		<description>but if you disable your browser&apos;s java support, you&apos;re just fine. so, do that.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205177</guid>
		<pubDate>Fri, 01 Aug 2008 13:43:22 -0800</pubDate>
		<dc:creator>saulgoodman</dc:creator>
	</item>	<item>
		<title>By: saulgoodman</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205182</link>	
		<description>&lt;em&gt;the web page would have to say &quot;Hey! There&apos;s Java on this here page, kick up your JVM&quot;, and that I would then attempt to compile the GIFAR and run it&lt;/em&gt;

if your browser is configured to allow java execution, the java client just runs the code, without prompting you. doesn&apos;t matter if you&apos;re at a java intensive site or not.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205182</guid>
		<pubDate>Fri, 01 Aug 2008 13:45:44 -0800</pubDate>
		<dc:creator>saulgoodman</dc:creator>
	</item>	<item>
		<title>By: uncleozzy</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205184</link>	
		<description>&lt;i&gt;Do I have that backwards?&lt;/i&gt;

Nope you&apos;ve got it right, but they specify that the execution is called for externally:
&lt;blockquote&gt;Then they&apos;d trick the victim into visiting a malicious Web site, which would tell the victim&apos;s browser to go open the GIFAR&lt;/blockquote&gt;
And yeah, saul, pretty much the only reason my JVM ever gets called is for 1999-style GIF-in-a-lake effects (and occasionally the Yahoo crossword puzzle).  Disable it if it&apos;s a concern.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205184</guid>
		<pubDate>Fri, 01 Aug 2008 13:47:00 -0800</pubDate>
		<dc:creator>uncleozzy</dc:creator>
	</item>	<item>
		<title>By: damn dirty ape</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205194</link>	
		<description>&lt;i&gt;nothZxfti23 45X4

[NO CARRIER]&lt;/i&gt;

I&apos;m really surprised by all the people here who run serial cables to the datacenter mefi is hosted at. Perhaps we can spruce the site up with some ANSI color graphics and Door games.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205194</guid>
		<pubDate>Fri, 01 Aug 2008 13:52:36 -0800</pubDate>
		<dc:creator>damn dirty ape</dc:creator>
	</item>	<item>
		<title>By: ook</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205197</link>	
		<description>&lt;i&gt;can someone please explain why this hack would only work on Facebook-type sites?&lt;/i&gt;

I think that just being able to upload images isn&apos;t even sufficient for this to be a real vulnerability.

So: the attacker uploads a JAR which the server thinks is a GIF but the victim&apos;s client executes it as a java applet.  So far so good.  But for most cases that wouldn&apos;t be any different than executing any other java applet on purpose; java can&apos;t access any data outside its own little sandbox.

The catch seems to be that a GIFAR runs with the privileges of the hosting site, not that of a random untrusted applet.  So if somebody attacked you via facebook, for example, they&apos;d be able to access only whatever information facebook would have access to if they had delivered the java applet to you directly -- but the attacker would still be limited to facebook&apos;s sandbox, they wouldn&apos;t be able to just dig at will through your hard drive.  I assume this is why the report says &quot;The victim would have to be logged into the Web site that is hosting the image for the attack to work.&quot;

I don&apos;t speak much java, so I&apos;m not exactly sure how much of a problem that would be in real terms -- I guess an attack of this type via facebook could maybe get hold of your facebook login info, for example.  Your bank statements will still be safe, though.

(And I&apos;m not certain, but it might also be necessary for the hosting site to be using java for legitimate purposes for this to be a vulnerability, in order for there to be any interesting data for a GIFAR to gain access to.   If that&apos;s the case, then this is a pretty tiny window of attack: only works on sites which use java for sensitive data and allow users to upload images for other users to view.  Nifty hack, though.)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205197</guid>
		<pubDate>Fri, 01 Aug 2008 13:53:47 -0800</pubDate>
		<dc:creator>ook</dc:creator>
	</item>	<item>
		<title>By: finite</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205199</link>	
		<description>&lt;em&gt;can someone please explain why this hack would only work on Facebook-type sites? Why wouldn&apos;t such an image be able to be displayed on any site?&lt;/em&gt;

Their malicious java applet is only able to steal cookies from (and do XmlHttpRequests to) the domain that it &lt;a href=&quot;http://en.wikipedia.org/wiki/Same_origin_policy&quot;&gt;originated&lt;/a&gt; from. So, when you load malicious code &lt;em&gt;from a site that you are logged in to&lt;/em&gt;, then your authentication credentials (&lt;a href=&quot;http://en.wikipedia.org/wiki/HTTP_cookie&quot;&gt;cookies&lt;/a&gt;) for that site can be compromised. See &lt;a href=&quot;http://en.wikipedia.org/wiki/Cross-site_scripting&quot;&gt;cross-site scripting&lt;/a&gt; for more details. So, social networking sites are ideal for this kind of attack because (a) they let you upload things and (b) people often stay logged in to them while browsing other sites (so, a hidden frame on another random site may covertly load a page from a site that you are logged into steal your cookies from there).

One way to mitigate this particular problem (and many others) is to only enable Java when you actually need to use it (which I haven&apos;t in weeks).</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205199</guid>
		<pubDate>Fri, 01 Aug 2008 13:54:00 -0800</pubDate>
		<dc:creator>finite</dc:creator>
	</item>	<item>
		<title>By: TheOnlyCoolTim</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205200</link>	
		<description>Yeah, I just disabled Java. The two times a year that I end up needing it on a website, I can turn it back on.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205200</guid>
		<pubDate>Fri, 01 Aug 2008 13:54:11 -0800</pubDate>
		<dc:creator>TheOnlyCoolTim</dc:creator>
	</item>	<item>
		<title>By: greensweater</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205202</link>	
		<description>&quot;The Internet Is Broken&quot; 

Are we sure this title is alarmist enough? Does NetCraft confirm this? Is our children learning???</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205202</guid>
		<pubDate>Fri, 01 Aug 2008 13:55:31 -0800</pubDate>
		<dc:creator>greensweater</dc:creator>
	</item>	<item>
		<title>By: ook</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205206</link>	
		<description>Yeah, now that I look, public&apos;s &lt;a href=&quot;http://radar.oreilly.com/2008/06/partial-same-origin-bypass-wit.html&quot;&gt;o&apos;reilly link&lt;/a&gt; up there seems to confirm that last part: &lt;strong&gt;&quot;assuming the web server runs a JVM&lt;/strong&gt;, it allows one to run a malicious java applet on someone else&apos;s web server.&quot;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205206</guid>
		<pubDate>Fri, 01 Aug 2008 13:58:39 -0800</pubDate>
		<dc:creator>ook</dc:creator>
	</item>	<item>
		<title>By: delmoi</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205210</link>	
		<description>It sounds like this is actually a lot less of a problem then it sounds like.  For one thing, the GIFAR will be shown as a GIF initially, you would need to load it from inside an applet tag or object tag, and if the site you&apos;re on allows those tags, then you can do a lot of other things too.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205210</guid>
		<pubDate>Fri, 01 Aug 2008 14:01:01 -0800</pubDate>
		<dc:creator>delmoi</dc:creator>
	</item>	<item>
		<title>By: mkb</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205217</link>	
		<description>&lt;i&gt;So: the attacker uploads a JAR which the server thinks is a GIF but the victim&apos;s client executes it as a java applet. So far so good. But for most cases that wouldn&apos;t be any different than executing any other java applet on purpose; java can&apos;t access any data outside its own little sandbox.&lt;/i&gt;

The attacker uploads a file that has a valid GIF at the start of the file and a valid JAR file (a ZIP file with headers at the END) at the end of the file. Loading this as an image with an &amp;lt;img&amp;gt; tag in your browser is not going to do anything but display the image. The attacker has to trick you into viewing a page with a complementary &amp;lt;applet&amp;gt; tag. that then loads and executes the JAR.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205217</guid>
		<pubDate>Fri, 01 Aug 2008 14:02:45 -0800</pubDate>
		<dc:creator>mkb</dc:creator>
	</item>	<item>
		<title>By: quin</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205221</link>	
		<description>&lt;em&gt;Are we sure this title is alarmist enough?&lt;/em&gt;

The Internet Emits A High Frequency Wave That Is Both Lobotomizing You And Giving You Cancer. Also, It Is Selling Your Children Marijuana Laced With Horse Tranquilizers and It Took Out Insurance On Your House And It&apos;s Planning On Torching The Place, Collecting The Money, And Then Skipping Town.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205221</guid>
		<pubDate>Fri, 01 Aug 2008 14:04:41 -0800</pubDate>
		<dc:creator>quin</dc:creator>
	</item>	<item>
		<title>By: mkb</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205226</link>	
		<description>&lt;i&gt;&quot;assuming the web server runs a JVM, it allows one to run a malicious java applet on someone else&apos;s web server.&quot;&lt;/i&gt;

I think the author of that entry is missing something. This is an attack on a client. Do web servers typically try to load image files as JARs, even if they have a JVM?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205226</guid>
		<pubDate>Fri, 01 Aug 2008 14:05:34 -0800</pubDate>
		<dc:creator>mkb</dc:creator>
	</item>	<item>
		<title>By: ook</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205247</link>	
		<description>Yeah, now that you mention it, I think you&apos;re right, mkb; that doesn&apos;t make a lot of sense. (I also think you&apos;re probably right about the &amp;lt;applet&amp;gt; tag, which may be where that confusion came from.)

In any case, this is sounding less like &quot;the internet is broken&quot; than &quot;the internet is vulnerable to Rube Goldberg&quot;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205247</guid>
		<pubDate>Fri, 01 Aug 2008 14:12:42 -0800</pubDate>
		<dc:creator>ook</dc:creator>
	</item>	<item>
		<title>By: ciderwoman</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205263</link>	
		<description>quonsar in arsehole shocker.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205263</guid>
		<pubDate>Fri, 01 Aug 2008 14:19:43 -0800</pubDate>
		<dc:creator>ciderwoman</dc:creator>
	</item>	<item>
		<title>By: StickyCarpet</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205279</link>	
		<description>Bring. It. On!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205279</guid>
		<pubDate>Fri, 01 Aug 2008 14:30:35 -0800</pubDate>
		<dc:creator>StickyCarpet</dc:creator>
	</item>	<item>
		<title>By: davejay</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205281</link>	
		<description>I can&apos;t tell you how sad I am that I can&apos;t find a clip of Jafar getting his eyes examined from that Family Guy episode, liked with the text &quot;Jafar after Goatse GIFAR.&quot;

&lt;small&gt;sigh&lt;/small&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205281</guid>
		<pubDate>Fri, 01 Aug 2008 14:32:01 -0800</pubDate>
		<dc:creator>davejay</dc:creator>
	</item>	<item>
		<title>By: pwb503</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205287</link>	
		<description>Isn&apos;t this the same reason we no longer can use the image tag on metafilter?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205287</guid>
		<pubDate>Fri, 01 Aug 2008 14:39:15 -0800</pubDate>
		<dc:creator>pwb503</dc:creator>
	</item>	<item>
		<title>By: tommasz</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205302</link>	
		<description>First it takes your childlike sense of innocence, then it takes your cash.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205302</guid>
		<pubDate>Fri, 01 Aug 2008 14:52:15 -0800</pubDate>
		<dc:creator>tommasz</dc:creator>
	</item>	<item>
		<title>By: Brak</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205307</link>	
		<description>This sounds like another variation on cross-site scripting, which I attack with good user practices at this point; I access any websites with sensitive information &lt;a href=&quot;http://articles.bluishcoder.co.nz/article/start-firefox-in-separate-process/&quot;&gt;in a separate browser process&lt;/a&gt; from other casual browsing, which in turn isolates my sensitive authentication information from potentially malicious code the latter group.  Or sometimes, when I&apos;m feeling &lt;i&gt;really&lt;/i&gt; paranoid, I close down all of my browsers, before opening a new one to do bank transactions or whatnot.

I know the whole &apos;the internet is broken&apos; thing reeks of hyperbole, but I have to admit, my introduction to the cross-site scripting class of vulnerabilities was the first time in a long time that I had to stop and reassess my (already pretty stringent) strategies for safe internet access.  And given the subtleties in those types of attacks, even to my tech/security-centric thinking, I projected their effect on my non-tech-savvy friends and relations, and wept silently for the identity theft to come.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205307</guid>
		<pubDate>Fri, 01 Aug 2008 14:55:16 -0800</pubDate>
		<dc:creator>Brak</dc:creator>
	</item>	<item>
		<title>By: LarryC</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205364</link>	
		<description>I don&apos;t understand any of this stuff, but didn&apos;t this come up a year or two ago and isn&apos;t it the reason that Matt pulled the image tag?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205364</guid>
		<pubDate>Fri, 01 Aug 2008 15:47:16 -0800</pubDate>
		<dc:creator>LarryC</dc:creator>
	</item>	<item>
		<title>By: srboisvert</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205378</link>	
		<description>I too have a giant gaping 0 in my bank account.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205378</guid>
		<pubDate>Fri, 01 Aug 2008 15:56:22 -0800</pubDate>
		<dc:creator>srboisvert</dc:creator>
	</item>	<item>
		<title>By: quonsar</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205402</link>	
		<description>&lt;i&gt;but didn&apos;t this come up a year or two ago and isn&apos;t it the reason that Matt pulled the image tag?&lt;/i&gt;

no.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205402</guid>
		<pubDate>Fri, 01 Aug 2008 16:20:49 -0800</pubDate>
		<dc:creator>quonsar</dc:creator>
	</item>	<item>
		<title>By: Malor</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205421</link>	
		<description>Different security issue, but he did originally pull them for security.  Gotta love it when security bugs result in a better outcome. :)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205421</guid>
		<pubDate>Fri, 01 Aug 2008 16:36:48 -0800</pubDate>
		<dc:creator>Malor</dc:creator>
	</item>	<item>
		<title>By: mr_crash_davis</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205452</link>	
		<description>&lt;i&gt;&quot;I close down all of my browsers, before opening a new one to do bank transactions or whatnot.&quot;&lt;/i&gt;

This is my usual method.

If it&apos;s &lt;i&gt;really sensitive&lt;/i&gt; data, I buy a new laptop, use it, then burn it afterward.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205452</guid>
		<pubDate>Fri, 01 Aug 2008 17:10:42 -0800</pubDate>
		<dc:creator>mr_crash_davis</dc:creator>
	</item>	<item>
		<title>By: shakespeherian</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205455</link>	
		<description>The Jafar puns make me wonder why people pronounce &lt;a href=&quot;http://en.wikipedia.org/wiki/Graphics_Interchange_Format&quot;&gt;gif&lt;/a&gt; with a soft g.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205455</guid>
		<pubDate>Fri, 01 Aug 2008 17:11:59 -0800</pubDate>
		<dc:creator>shakespeherian</dc:creator>
	</item>	<item>
		<title>By: bh</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205471</link>	
		<description>&lt;i&gt;The Jafar puns make me wonder why people pronounce gif with a soft g.&lt;/i&gt;

For the same reason people pronounce Linux the way they do.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205471</guid>
		<pubDate>Fri, 01 Aug 2008 17:23:20 -0800</pubDate>
		<dc:creator>bh</dc:creator>
	</item>	<item>
		<title>By: graventy</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205541</link>	
		<description>Because choosy moms choose gif.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205541</guid>
		<pubDate>Fri, 01 Aug 2008 18:24:28 -0800</pubDate>
		<dc:creator>graventy</dc:creator>
	</item>	<item>
		<title>By: Mitheral</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205686</link>	
		<description>&lt;b&gt;porn in the woods&lt;/b&gt; &lt;a href=&apos;http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205171&apos;&gt;writes&lt;/a&gt;  &lt;em&gt;&quot;&lt;small&gt;[NO CARRIER]&lt;/small&gt;&quot;&lt;/em&gt;

I wonder whether anyone born after 1985 or so gets this bit.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205686</guid>
		<pubDate>Fri, 01 Aug 2008 22:37:24 -0800</pubDate>
		<dc:creator>Mitheral</dc:creator>
	</item>	<item>
		<title>By: breath</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205737</link>	
		<description>&lt;i&gt;Their malicious java applet is only able to steal cookies from (and do XmlHttpRequests to) the domain that it originated from. &lt;/i&gt;

The simple solution for any social site is to serve up images from a different domain.  I.e. facebook should serve up its images from facebookimages.com, or just the ip address, 69.63.176.140.

This general class of attack and the defenses against it are pretty well discussed in &lt;a href=&quot;http://www.amazon.com/exec/obidos/ASIN/0071494618/metafilter-20/ref=nosim/&quot;&gt;this book&lt;/a&gt;.  [disclaimer: I am friends with one of the authors]</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205737</guid>
		<pubDate>Sat, 02 Aug 2008 01:35:54 -0800</pubDate>
		<dc:creator>breath</dc:creator>
	</item>	<item>
		<title>By: Jimbob</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205776</link>	
		<description>After watching java.exe sit there taking up 90-odd meg of RAM on my low-spec laptop, and watching the process restart itself every time I tried to kill it off, I uninstalled Java last week (and am currently loving the new lease on life all that memory being returned has given this old beast).  I can&apos;t remember the last time I used Java for anything &lt;i&gt;useful&lt;/i&gt;, although I was into Processing for a while.  Now my decision is feeling even smarter.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205776</guid>
		<pubDate>Sat, 02 Aug 2008 03:46:18 -0800</pubDate>
		<dc:creator>Jimbob</dc:creator>
	</item>	<item>
		<title>By: uncleozzy</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205897</link>	
		<description>&lt;i&gt;The Jafar puns make me wonder why people pronounce gif with a soft g.&lt;/i&gt;

Hey man, when I downloaded my first grainy, monochrome GIF of Marina Sirtis&apos; face composited onto a nudie shot, that was the common pronunciation.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205897</guid>
		<pubDate>Sat, 02 Aug 2008 08:10:52 -0800</pubDate>
		<dc:creator>uncleozzy</dc:creator>
	</item>	<item>
		<title>By: effugas</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205980</link>	
		<description>OK, I know Heasman.  I&apos;ve worked in the same office as Heasman.  He&apos;s awesome.  He&apos;s been doing some fantastically tricky thing to Java as of late.

The GIFAR thing is a known class of issue.  We&apos;ve been having GIFs that can render as Javascript for years.  This, specifically, is why it&apos;s not safe for any site to allow user generated files to be loaded from a domain that contains private data.  And that&apos;s what you see, generally, in the field -- MySpace hosting their images from myspacecdn, Flickr from yimg, Google Cache from IP addresses, and so on.

Browser security is something of a hack, but it gets a lot more crap than it should.  It does actually work a lot better than a lot of other things.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205980</guid>
		<pubDate>Sat, 02 Aug 2008 10:15:04 -0800</pubDate>
		<dc:creator>effugas</dc:creator>
	</item>	<item>
		<title>By: effugas</title>
		<link>http://www.metafilter.com/73771/lolcatting-all-the-way-to-the-bank#2205982</link>	
		<description>Regarding the killing of the img tag on Metafilter, I expect that has more to do with defenses against CSRF (Cross-Site Request Forgery) -- specifically, there used to be a decent number of ways a malicious img link could combine with your user credentials to mess things up.  REST is unfortunately beautiful but difficult to secure, and vulnerability to img links is one of its traits.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.73771-2205982</guid>
		<pubDate>Sat, 02 Aug 2008 10:17:33 -0800</pubDate>
		<dc:creator>effugas</dc:creator>
	</item>
	</channel>
</rss>
