Mailing List ArchiveSupport open source code!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: tlug: Cache cow security hole
- To: tlug@example.com
- Subject: Re: tlug: Cache cow security hole
- From: Darren Cook <darren@example.com>
- Date: Wed, 30 Sep 1998 22:08:20
- Content-Type: text/plain; charset="us-ascii"
- In-Reply-To: <Pine.LNX.3.96LJ1.1b7.980930211026.10709A-100000@example.com>
- Reply-To: tlug@example.com
- Sender: owner-tlug@example.com
>Here's a site everybody should check out, if they haven't already seen it. >It is possible to suck out all of Netscape's cached information, including >credit card numbers (yup, it saves those!) without your knowing it. Credit card numbers is a bit of an exaggeration. "about:cache" only shows URL's, which means it would only store form information if submitted with "GET", which is very unusual (if you did that your credit card number would be in any proxies it passed through, and the server logs as well). I just tried a "POST" form, and none of the information I submitted is there. I wonder how Netscape are going to stop this problem without disabling useful functionality? I suppose you could stop submit() being called from an onLoad() command, which is always likely to be devious. Darren --------------------------------------------------------------- Next Meeting: 10 October, 12:30 Tokyo Station Yaesu central gate Featuring the IMASY Eng. Team on "IPv6 - The Next Generation IP" Next Nomikai: 20 November, 19:30 Tengu TokyoEkiMae 03-3275-3691 --------------------------------------------------------------- Sponsor: PHT, makers of TurboLinux http://www.pht.co.jp
- References:
- tlug: Cache cow security hole
- From: Jonathan Byrne <jq@example.com>
Home | Main Index | Thread Index
- Prev by Date: tlug: Linux for the masses: a civil reply, I hope.
- Next by Date: Re: tlug: Cache cow security hole
- Prev by thread: tlug: Cache cow security hole
- Next by thread: Re: tlug: Cache cow security hole
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links