<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: [RESOLVED] Second Life URL Handler Exploit</title>
	<atom:link href="http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/</link>
	<description>By Linden Lab</description>
	<pubDate>Tue, 02 Dec 2008 07:02:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Nikki Claymore</title>
		<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480584</link>
		<dc:creator>Nikki Claymore</dc:creator>
		<pubDate>Wed, 19 Sep 2007 14:58:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480584</guid>
		<description>Re: Firefox vulnerability debate. 

http://www.mozilla.org/security/announce/2007/mfsa2007-27.html

This issue can only occur for firefox users who don't update and are running prior to Firefox 2.0.0.6 current version is Firefox 2.0.0.7.</description>
		<content:encoded><![CDATA[<p>Re: Firefox vulnerability debate. </p>
<p><a href="http://www.mozilla.org/security/announce/2007/mfsa2007-27.html" rel="nofollow">http://www.mozilla.org/security/announce/2007/mfsa2007-27.html</a></p>
<p>This issue can only occur for firefox users who don&#8217;t update and are running prior to Firefox 2.0.0.6 current version is Firefox 2.0.0.7.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sofia Westwick</title>
		<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480245</link>
		<dc:creator>Sofia Westwick</dc:creator>
		<pubDate>Wed, 19 Sep 2007 12:37:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480245</guid>
		<description>Its not just about voice its abotu the interface. The voice one is very differnet then 1.18.0.6. and alot of us do not want to be stuck with the new interface.

So we will be happy with one same style as 1.18.0.6</description>
		<content:encoded><![CDATA[<p>Its not just about voice its abotu the interface. The voice one is very differnet then 1.18.0.6. and alot of us do not want to be stuck with the new interface.</p>
<p>So we will be happy with one same style as 1.18.0.6</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tammy Nowotny</title>
		<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480239</link>
		<dc:creator>Tammy Nowotny</dc:creator>
		<pubDate>Wed, 19 Sep 2007 12:16:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480239</guid>
		<description>About the voice viewer problem: you can simply Edit the Preferences and turn off Voice Chat.  There is a checkbox on the Voice Chat tab.  The new viewer still has a slightly different chat window, but at least you will now not have voice.</description>
		<content:encoded><![CDATA[<p>About the voice viewer problem: you can simply Edit the Preferences and turn off Voice Chat.  There is a checkbox on the Voice Chat tab.  The new viewer still has a slightly different chat window, but at least you will now not have voice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unmitigated Gall</title>
		<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480164</link>
		<dc:creator>Unmitigated Gall</dc:creator>
		<pubDate>Wed, 19 Sep 2007 09:35:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480164</guid>
		<description>Strange that all calls using the "secondlife//" http reqest are now considered someone trying to exploit the vulnerability. I have used that call for years to link people into the game from email. All that has changed is you have become aware that someone is now using a hack to get user info. The only change you should make is removal of the "Remember Password" box. Issue solved, all platforms and viewers.</description>
		<content:encoded><![CDATA[<p>Strange that all calls using the &#8220;secondlife//&#8221; http reqest are now considered someone trying to exploit the vulnerability. I have used that call for years to link people into the game from email. All that has changed is you have become aware that someone is now using a hack to get user info. The only change you should make is removal of the &#8220;Remember Password&#8221; box. Issue solved, all platforms and viewers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unmitigated Gall</title>
		<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480160</link>
		<dc:creator>Unmitigated Gall</dc:creator>
		<pubDate>Wed, 19 Sep 2007 09:16:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480160</guid>
		<description>TAMARA,

MANY OF US DO WANT VOICE. VERY SIMPLE, YOU DONT WANT IT, DONT ACTIVATE IT? SO DAM SIMPLE.</description>
		<content:encoded><![CDATA[<p>TAMARA,</p>
<p>MANY OF US DO WANT VOICE. VERY SIMPLE, YOU DONT WANT IT, DONT ACTIVATE IT? SO DAM SIMPLE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jabath Steuart</title>
		<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480153</link>
		<dc:creator>Jabath Steuart</dc:creator>
		<pubDate>Wed, 19 Sep 2007 08:56:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480153</guid>
		<description>I posted the link above so you could read the tips, if you want to use the password strength meter, please follow this advice:

"Please note that although we will not store the password you enter, it's never a good idea to send your password to someone you don't know. Instead, we recommend testing a password which is *similar* to one you might use."</description>
		<content:encoded><![CDATA[<p>I posted the link above so you could read the tips, if you want to use the password strength meter, please follow this advice:</p>
<p>&#8220;Please note that although we will not store the password you enter, it&#8217;s never a good idea to send your password to someone you don&#8217;t know. Instead, we recommend testing a password which is *similar* to one you might use.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jabath Steuart</title>
		<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480149</link>
		<dc:creator>Jabath Steuart</dc:creator>
		<pubDate>Wed, 19 Sep 2007 08:53:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480149</guid>
		<description>For those who don't understand the jargon, here is the exploit:

You go to a web page in Internet Explorer with SL not running, the webpage has some nasty code in it that launches SL (through what they call a url handler) and tries to log in.  BUT the code tells SL to log in to the nasty cracker's server, not the LL server.  If you have the "remember password" box checked on the SL login screen, your password is sent to the cracker's server. Your login will then fail.

If SL IS running when you go to the bad web page, it will not try to log in, and it won't send your password. The map might pop up though.

If you are using Firefox and not IE, the same thing happens, except firefox does the urlhandler thing properly, and SL wont send your password to the cracker.

Q: Who's fault is this?  LL and Microsoft
Q: What should I do about it?
A: Minimum: Uncheck the Remember Password box and wait for the update. 
Reasonable: Set IE security settings to high and never use it again. Install Firefox or Opera browser and set it to be your default browser. Change your SL password (and all your other passwords) bi-monthly or better. Use a password of at least 8 characters using lowercase and uppercase letters, numbers and at least one symbol

http://www.securitystats.com/tools/password.php</description>
		<content:encoded><![CDATA[<p>For those who don&#8217;t understand the jargon, here is the exploit:</p>
<p>You go to a web page in Internet Explorer with SL not running, the webpage has some nasty code in it that launches SL (through what they call a url handler) and tries to log in.  BUT the code tells SL to log in to the nasty cracker&#8217;s server, not the LL server.  If you have the &#8220;remember password&#8221; box checked on the SL login screen, your password is sent to the cracker&#8217;s server. Your login will then fail.</p>
<p>If SL IS running when you go to the bad web page, it will not try to log in, and it won&#8217;t send your password. The map might pop up though.</p>
<p>If you are using Firefox and not IE, the same thing happens, except firefox does the urlhandler thing properly, and SL wont send your password to the cracker.</p>
<p>Q: Who&#8217;s fault is this?  LL and Microsoft<br />
Q: What should I do about it?<br />
A: Minimum: Uncheck the Remember Password box and wait for the update.<br />
Reasonable: Set IE security settings to high and never use it again. Install Firefox or Opera browser and set it to be your default browser. Change your SL password (and all your other passwords) bi-monthly or better. Use a password of at least 8 characters using lowercase and uppercase letters, numbers and at least one symbol</p>
<p><a href="http://www.securitystats.com/tools/password.php" rel="nofollow">http://www.securitystats.com/tools/password.php</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sofia Westwick</title>
		<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480124</link>
		<dc:creator>Sofia Westwick</dc:creator>
		<pubDate>Wed, 19 Sep 2007 07:51:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480124</guid>
		<description>Please do keep a viewer alive for us who can't use Voice for hearing reasons or us who just don't want to bother with it.  I my self am using the 1.18.0.6 client. and I would like to keep using this style I prefer the 1.18.0.6 interface and none voice over the other viewers/client interfaces. I do not want to be forced to use the voice style update and interface

All of us who use the 1.18.0.6 style would be very greatful for a version like this when the the required upgrade is out.</description>
		<content:encoded><![CDATA[<p>Please do keep a viewer alive for us who can&#8217;t use Voice for hearing reasons or us who just don&#8217;t want to bother with it.  I my self am using the 1.18.0.6 client. and I would like to keep using this style I prefer the 1.18.0.6 interface and none voice over the other viewers/client interfaces. I do not want to be forced to use the voice style update and interface</p>
<p>All of us who use the 1.18.0.6 style would be very greatful for a version like this when the the required upgrade is out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: void singer</title>
		<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480101</link>
		<dc:creator>void singer</dc:creator>
		<pubDate>Wed, 19 Sep 2007 07:09:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480101</guid>
		<description>::desperately misses the old ui for multiple reasons, new is too blocky, im now tied to new oversized communicate, loss of "alt shows..., etc::

for those that still want the old saved pw function, but not the vunerability try modifing a shortcut to seccondlife to the following:

"C:\Program Files\SecondLife\SecondLife.exe" -login first last password

change first last and password to your own info
this will connect you automatically to whatever your location is set to skipping the info page. IF YOU WANT THE INFO PAGE, DON'T THIS!

if you hate that it redetects your hardware EVERY time add -noprobe before -login (by itself this won't cause you to skip the info page)

if you want to make it log into a specific location add -url secondlife://region/x/y/z to the end

replace region and xyz with the sim name and coordinates. you can use this w/o the others to set your login location and still keep the info page

example:

"C:\Program Files\SecondLife\SecondLife.exe"   -noprobe -login your name password -url secondlife://ahern/128/128/0

IMPORTANT NOTE: anyone that click on the shorcut can see you password if you specify it, so you probably shouldn't do this if you share your destop with another user. dunno what the equivalent for Mac users is, linux users can obviously figure out the difference

- Void</description>
		<content:encoded><![CDATA[<p>::desperately misses the old ui for multiple reasons, new is too blocky, im now tied to new oversized communicate, loss of &#8220;alt shows&#8230;, etc::</p>
<p>for those that still want the old saved pw function, but not the vunerability try modifing a shortcut to seccondlife to the following:</p>
<p>&#8220;C:\Program Files\SecondLife\SecondLife.exe&#8221; -login first last password</p>
<p>change first last and password to your own info<br />
this will connect you automatically to whatever your location is set to skipping the info page. IF YOU WANT THE INFO PAGE, DON&#8217;T THIS!</p>
<p>if you hate that it redetects your hardware EVERY time add -noprobe before -login (by itself this won&#8217;t cause you to skip the info page)</p>
<p>if you want to make it log into a specific location add -url secondlife://region/x/y/z to the end</p>
<p>replace region and xyz with the sim name and coordinates. you can use this w/o the others to set your login location and still keep the info page</p>
<p>example:</p>
<p>&#8220;C:\Program Files\SecondLife\SecondLife.exe&#8221;   -noprobe -login your name password -url secondlife://ahern/128/128/0</p>
<p>IMPORTANT NOTE: anyone that click on the shorcut can see you password if you specify it, so you probably shouldn&#8217;t do this if you share your destop with another user. dunno what the equivalent for Mac users is, linux users can obviously figure out the difference</p>
<p>- Void</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: U M</title>
		<link>http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480070</link>
		<dc:creator>U M</dc:creator>
		<pubDate>Wed, 19 Sep 2007 06:15:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.secondlife.com/2007/09/18/second-life-url-handler-exploit/#comment-480070</guid>
		<description>@ 89 everyone knew this woud happen. Many caleld for safe measures. But LL didnt pat any attention until someone causes this problem to be noticed. A little too late as always don`t you think.</description>
		<content:encoded><![CDATA[<p>@ 89 everyone knew this woud happen. Many caleld for safe measures. But LL didnt pat any attention until someone causes this problem to be noticed. A little too late as always don`t you think.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
