[Full-disclosure] Firefox + popup blocker + XMLHttpRequest + srand() = oops

James Matthews nytrokiss at gmail.com
Mon Feb 5 20:09:27 GMT 2007


Do you think it will be patched??

On 2/5/07, Michal Zalewski <lcamtuf at dione.ids.pl> wrote:
>
> On Mon, 5 Feb 2007, pdp (architect) wrote:
>
> > You may as well use a QuickTime .mov/.qtl or a PDF document to open a
> > file:// link . I think it is easier.
>
> Sure. You can probably have a file:// link in Open Office / MS Office
> documents as well; but these all rely on external components, and as such,
> attacks could be shrugged off as a weakness in these apps (and there's
> some truth to this).
>
> Browser authors know better, and they disallow file:// URLs from the
> Internet ever since Javascript became so powerful; this case managed to
> slip through, so I thought it's a neat example, in conjunction with
> deterministic temporary files.
>
> /mz
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>



-- 
http://www.goldwatches.com
http://www.wazoozle.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20070205/2607e14d/attachment.html 


Full-Disclosure is hosted and sponsored by Secunia.