<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Safari "carpet bombing" Fail Open Goat Award</title><link>http://blogs.technet.com/b/robert_hensing/archive/2008/05/22/safari-carpet-bombing-fail-open-goat-award.aspx</link><description>So last week Nitesh and Billy Rios found a vuln in Safari that lets a remote attacker / malicious web site drop any file(s) they want on a users desktop if you're using Safari on Windows. Apple doesn't see this as a security vulnerability and thus isn</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Ah, the irony! Microsoft says Safari isn't safe on Windows</title><link>http://blogs.technet.com/b/robert_hensing/archive/2008/05/22/safari-carpet-bombing-fail-open-goat-award.aspx#3064260</link><pubDate>Sat, 31 May 2008 18:04:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3064260</guid><dc:creator>TechBlog</dc:creator><description>&lt;p&gt;Apple's been making hay in its Mac vs. PC ads about Windows' security and malware problems. But now that Apple's playing in Microsoft's sandbox with a Windows version of the Safari Web browser, the worm has turned. The Windows version...&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3064260" width="1" height="1"&gt;</description></item><item><title>Why Apple has to fix the Safari flaw</title><link>http://blogs.technet.com/b/robert_hensing/archive/2008/05/22/safari-carpet-bombing-fail-open-goat-award.aspx#3063303</link><pubDate>Fri, 30 May 2008 10:20:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3063303</guid><dc:creator>Roger's Security Blog</dc:creator><description>&lt;p&gt;Remember me talking about Is Security Research Ethical? I made a statement in there when it comes to&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3063303" width="1" height="1"&gt;</description></item><item><title>
		Why Apple must fix Safari &amp;#8216;carpet bombing&amp;#8217; flaw immediately | Zero Day 
		| ZDNet.com
	</title><link>http://blogs.technet.com/b/robert_hensing/archive/2008/05/22/safari-carpet-bombing-fail-open-goat-award.aspx#3062906</link><pubDate>Thu, 29 May 2008 22:41:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3062906</guid><dc:creator>
		Why Apple must fix Safari &amp;#8216;carpet bombing&amp;#8217; flaw immediately | Zero Day 
		| ZDNet.com
	</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://blogs.zdnet.com/security/?p=1212"&gt;http://blogs.zdnet.com/security/?p=1212&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3062906" width="1" height="1"&gt;</description></item></channel></rss>