I WUV YOU was just the beginning.
IE now executes *.js files on your PC.

I hope and pray IE is never ported to Linux.
Read on for more.

--
Rick Welykochy || Praxis Services
--


---------- Forwarded message ----------
Date: Mon, 8 May 2000 22:50:30 -0400
From: Michael Sims <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: [LINK] (Fwd) Internet Explorer exposing passwords, history, etc.

Since Link seemed to be interested in the details of yet another IE 
security hole, here you go.  The hostile website must know of a file 
named *.js existing on your computer - which IE will cheerfully 
execute, since, after all, it's on your computer and therefore must be 
safe to run.  Netscape's only culpability lies in not anticipating 
another Microsoft security hole.


------- Forwarded message follows -------
Date sent:              Fri, 05 May 2000 14:20:10 -0700
From:                   Bennett Haselton <[EMAIL PROTECTED]>
Subject:                Internet Explorer exposing passwords, history, etc.

New trick:

http://www.peacefire.org/security/localjs/

It turns out IE will let you load the Netscape prefs.js file as a
JavaScript file even on a page which isn't local.  So you can overload the
user_pref() function (which is called repeatedly in prefs.js) so that
loading prefs.js causes all the Preferences data (including browsing
history, and -- if you use Netscape Mail to read your mail -- your email
address, name and POP mail password) to be sent to the hostile Web site.

        -Bennett

[EMAIL PROTECTED]     http://www.peacefire.org
(425) 649 9024

------- End of forwarded message -------


--
Michael Sims -  The Censorware Project - http://censorware.org
                Your Rights Online  -  http://slashdot.org/yro
If you can't answer a man's argument, all is not lost; you can still call
him vile names.

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to