Re: cookies taste good, was: Re: Java
by "Paul Witheridge" <ssuccess(at)ebtech.net>
|
| Date: |
Sat, 30 Mar 2002 07:17:47 -0500 |
| To: |
hwg-basics(at)hwg.org |
| References: |
gte |
| |
todo: View
Thread,
Original
|
|
On 29 Mar 2002, at 22:58, jim barchuk said
> Hello All!
>
> > > I know nothing of Java folks. But you both admit to its being
> > > able to write ASCII text to cookies -- simple text files (which
> > > requires it to find your cookie cache). So why can't it write
> > > ASCII text to AUTOEXEC.BAT -- another simple text file, and not
> > > Read-only -- which is *always* located in C:\ ? And we all know
> > > that a website can lock up your browser leading many to reboot.
> > > The combination sounds too potentially dangerous to me.
>
> How timely that MS just came out with Security Bulletin MS02-015, 'a
> zone determiniation vulnerability that could allow a script embedded
> in a cookie by an Internet zone to run in the Local Computer zone.'
>
> This one is labeled 'critical' and 'install patch immediately.'
> Affects IE 5.01, 5.5, 6.
>
> http://www.microsoft.com/technet/security/bulletin/ms02-015.asp
Gotta admit, I hesitated posting the details of that one when I saw it
since I'm on such shaky ground on this subject but since Jim has
brought it up...
<quote>
> A vulnerability in the zone determination function that could allow
> a script embedded in a cookie to be run in the Local Computer zone.
> While HTML scripts can be stored in cookies, they should be handled
> in the same zone as the hosting site associated with them, in most
> cases the Internet zone. An attacker could place script in a cookie
> that would be saved to the user=92s hard disk. When the cookie was
> opened by the site the script would then run in the Local Computer
> zone, allowing it to run with fewer restrictions than it would
> otherwise have.
>
> A vulnerability in the handling of object tags that could allow an
> attacker to invoke an executable already present on the user=92s
> machine. A malicious user could create HTML web page that includes
> this object tag and cause a local program to run on the victim=92s
> machine.
<unquote>
Best regards,
Paul Witheridge
Systems Success
ssuccess(at)ebtech.net
Do dentists wear masks because of their fees?
HTML: hwg-basics mailing list archives,
maintained by Webmasters @ IWA
This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.