Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] webmail password protection?



On 25/01/06, Josh Glover <jmglov@example.com> wrote:
On 25/01/06, Stephen J. Turnbull <stephen@example.com> wrote:
> X11 transmits all of these as events, so anybody with access to the X
> stream can see them.  You lose, unless the machine is running, say,
> Windows so there are no X events.  I don't think Mac OS or Windows
> have such event streams, but who knows.

I am pretty sure Windows does, because WinAMP lets you define global
hotkeys, and I cannot think of how else they could work.

Indeed.  Wasn't there a security flaw which meant that (a) you could send an event to get pretty much anything to execute untrusted code and (b) you tried to send it to e.g. the virus scanner's UI, which was running priv'ed at the time?  The fix may have involved checking events properly in the Windows application (possibly the library). 

This is all from memory, so probably distorted.

--
Ian.

Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links