[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <45C7E7D4.5080603@bucksch.org>
Date: Tue, 06 Feb 2007 03:28:36 +0100
From: Ben Bucksch <news@...ksch.org>
To: full-disclosure@...ts.grok.org.uk
Cc: bugtraq@...urityfocus.com
Subject: Re: Firefox + popup blocker + XMLHttpRequest +
srand() = oops
No, we never patch bugs. Where would this lead us? Only commies taking over!
Tracked in bug 369390.
James Matthews wrote:
> Do you think it will be patched??
>
> On 2/5/07, *Michal Zalewski* <lcamtuf@...ne.ids.pl
> <mailto:lcamtuf@...ne.ids.pl>> wrote:
>
> On Mon, 5 Feb 2007, pdp (architect) wrote:
>
> > You may as well use a QuickTime .mov/.qtl or a PDF document to
> open a
> > file:// link . I think it is easier.
>
> Sure. You can probably have a file:// link in Open Office / MS Office
> documents as well; but these all rely on external components, and
> as such,
> attacks could be shrugged off as a weakness in these apps (and there's
> some truth to this).
>
> Browser authors know better, and they disallow file:// URLs from the
> Internet ever since Javascript became so powerful; this case
> managed to
> slip through, so I thought it's a neat example, in conjunction with
> deterministic temporary files.
>
> /mz
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
>
>
>
> --
> http://www.goldwatches.com
> http://www.wazoozle.com
> ------------------------------------------------------------------------
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists