I WUV YOU was just the beginning. IE now executes *.js files on your PC. I hope and pray IE is never ported to Linux. Read on for more. -- Rick Welykochy || Praxis Services -- ---------- Forwarded message ---------- Date: Mon, 8 May 2000 22:50:30 -0400 From: Michael Sims <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: [LINK] (Fwd) Internet Explorer exposing passwords, history, etc. Since Link seemed to be interested in the details of yet another IE security hole, here you go. The hostile website must know of a file named *.js existing on your computer - which IE will cheerfully execute, since, after all, it's on your computer and therefore must be safe to run. Netscape's only culpability lies in not anticipating another Microsoft security hole. ------- Forwarded message follows ------- Date sent: Fri, 05 May 2000 14:20:10 -0700 From: Bennett Haselton <[EMAIL PROTECTED]> Subject: Internet Explorer exposing passwords, history, etc. New trick: http://www.peacefire.org/security/localjs/ It turns out IE will let you load the Netscape prefs.js file as a JavaScript file even on a page which isn't local. So you can overload the user_pref() function (which is called repeatedly in prefs.js) so that loading prefs.js causes all the Preferences data (including browsing history, and -- if you use Netscape Mail to read your mail -- your email address, name and POP mail password) to be sent to the hostile Web site. -Bennett [EMAIL PROTECTED] http://www.peacefire.org (425) 649 9024 ------- End of forwarded message ------- -- Michael Sims - The Censorware Project - http://censorware.org Your Rights Online - http://slashdot.org/yro If you can't answer a man's argument, all is not lost; you can still call him vile names. -- SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au To unsubscribe send email to [EMAIL PROTECTED] with unsubscribe in the text
