[freenet-support] IE6/XP SP2 may no longer treat text/plain as ambiguous?

2006-12-01 Thread toad
Somebody with XP SP2 and IE6, please visit the below site, and tell me
if it redirects you to fbi.gov:

CHK at 
qhg6NvKnWfG~mKm1akieQfc70pqWXvlyqyBsOnyUZr0,F65SIZDVMBjP9U1Rm1qXK~9Yb8nITW9NO3GdJw3orR8,AAEC--8/

Thanks.

[1] below suggests that it may not. If so, we can drop the warning about
IE not honouring MIME types (for HTML) ... unfortunately, there is RSS
to worry about instead! So please check that too:

Visit the current edition of freenetwatch:
USK at 
jotJldLVFPDEnvRqfhBWsnXPQpOS~QrawxFjgsLZcFQ,xnNqE4Z~zMHmIUmqrA0oziUFSXNOAC7OhOOH4yhcBq4,AQABAAE/freenetwatch/38/

Click on the RSS feed. If you have a recent version of Freenet, this
will produce a warning page. Click on "open the file as plain text";
does it open the RSS feed as RSS, or does it show it as text? Same with
"force your browser to save it to disk" and "open the file as RSS"
please.

[1] 
http://msdn.microsoft.com/workshop/networking/moniker/overview/appendix_a.asp
-- next part --
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
URL: 
<https://emu.freenetproject.org/pipermail/support/attachments/20061201/29caab77/attachment.pgp>


[freenet-support] IE6/XP SP2 may no longer treat text/plain as ambiguous?

2006-12-01 Thread Ken Snider
toad wrote:
> Somebody with XP SP2 and IE6, please visit the below site, and tell me
> if it redirects you to fbi.gov:

On my sandbox box I use for such testing, it does redirect to fbi.gov.


> Visit the current edition of freenetwatch:
> USK at 
> jotJldLVFPDEnvRqfhBWsnXPQpOS~QrawxFjgsLZcFQ,xnNqE4Z~zMHmIUmqrA0oziUFSXNOAC7OhOOH4yhcBq4,AQABAAE/freenetwatch/38/
> 
> Click on the RSS feed. If you have a recent version of Freenet, this
> will produce a warning page. Click on "open the file as plain text";
> does it open the RSS feed as RSS, or does it show it as text? Same with
> "force your browser to save it to disk" and "open the file as RSS"
> please.

- save as plain text, does nothing.
- force download wants to save it as a text file, and
- open as RSS splats it out as unformatted RSS

-- 
Ken Snider



[freenet-support] Freenet 0.7 build 1005 including FF2 security fix

2006-12-01 Thread toad
Freenet 0.7 build 1005 is now available. Please upgrade. This build
fixes a potential security issue with Firefox 2.0 (also IE 7, but that
has other problems). Firefox will display as RSS anything which from the
first 512 bytes looks like RSS; therefore an attacker can bypass the
HTML filter using an RSS file with inline images inserted with a MIME
type of plain text. There is also a new per-peer option, "ignore source
port", which you should set (from the darknet page, in advanced mode),
if you are having trouble connecting to a peer behind a corporate NAT.
Finally there are some changes to the node-to-node text messaging
system, which hopefully will make it easier to track down a long-running
but rare bug, and there are some minor improvements to the web
interface.

Upgrade!
-- next part --
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
URL: 
<https://emu.freenetproject.org/pipermail/support/attachments/20061201/056e14d2/attachment.pgp>


[freenet-support] IE6/XP SP2 may no longer treat text/plain as ambiguous?

2006-12-01 Thread toad
Somebody with XP SP2 and IE6, please visit the below site, and tell me
if it redirects you to fbi.gov:

[EMAIL PROTECTED],F65SIZDVMBjP9U1Rm1qXK~9Yb8nITW9NO3GdJw3orR8,AAEC--8/

Thanks.

[1] below suggests that it may not. If so, we can drop the warning about
IE not honouring MIME types (for HTML) ... unfortunately, there is RSS
to worry about instead! So please check that too:

Visit the current edition of freenetwatch:
[EMAIL 
PROTECTED],xnNqE4Z~zMHmIUmqrA0oziUFSXNOAC7OhOOH4yhcBq4,AQABAAE/freenetwatch/38/

Click on the RSS feed. If you have a recent version of Freenet, this
will produce a warning page. Click on open the file as plain text;
does it open the RSS feed as RSS, or does it show it as text? Same with
force your browser to save it to disk and open the file as RSS
please.

[1] 
http://msdn.microsoft.com/workshop/networking/moniker/overview/appendix_a.asp


signature.asc
Description: Digital signature
___
Support mailing list
Support@freenetproject.org
http://news.gmane.org/gmane.network.freenet.support
Unsubscribe at http://emu.freenetproject.org/cgi-bin/mailman/listinfo/support
Or mailto:[EMAIL PROTECTED]