[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <bc7e11f20806180822q252e51brb9b1a37f880e303c@mail.gmail.com>
Date: Wed, 18 Jun 2008 17:22:51 +0200
From: "carl hardwick" <hardwick.carl@...il.com>
To: Full-Disclosure@...ts.grok.org.uk
Subject: Flaw in Firefox 3.0:
protocol-handler.warn-external are ignored
these protocol-handler security settings are ignored although they're
set to 'true' and no warnings are shown:
network.protocol-handler.warn-external.mailto
network.protocol-handler.warn-external.news
network.protocol-handler.warn-external.nntp
network.protocol-handler.warn-external.snews
(in about:config)
For example,
I set network.protocol-handler.warn-external.mailto to 'true', clicked
on an e-mail link and Windows Mail is launched without any warnings
(tested on Firefox 3.0 on Windows Vista SP1)
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists