Re: [Full-disclosure] When standards attack...

2008-03-21 Thread Florian Weimer
* H. D. Moore: > The WebKit folks just added client-side SQL database support: > > http://webkit.org/blog/126/webkit-does-html5-client-side-database-storage/ > http://glazkov.com/blog/html5-gears-wrapper/ > > In addition to all of the existing attacks through a web browser, we can > now take in

Re: [Full-disclosure] When standards attack...

2008-03-20 Thread KJK::Hyperion
H D Moore ha scritto: > ...because letting developers choose to bind their query parameters has > worked so well before ;-) HDM, why don't join the HTML5 working group? you or GNUcitizen? With your experience and credentials, you should have no problem getting your opinions heeded

[Full-disclosure] When standards attack...

2008-03-20 Thread H D Moore
The WebKit folks just added client-side SQL database support: http://webkit.org/blog/126/webkit-does-html5-client-side-database-storage/ http://glazkov.com/blog/html5-gears-wrapper/ In addition to all of the existing attacks through a web browser, we can now take into account SQLite vulnerabili