Mailing List ArchiveSupport open source code!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: tlug: Cache cow security hole
- To: tlug@example.com
- Subject: Re: tlug: Cache cow security hole
- From: Totoro <riley@example.com>
- Date: Thu, 1 Oct 1998 09:21:43 +0900 (JST)
- Content-Type: TEXT/PLAIN; charset=US-ASCII
- In-Reply-To: <3.0.6.32.19980930220820.009c2220@example.com>
- Reply-To: tlug@example.com
- Sender: owner-tlug@example.com
On Wed, 30 Sep 1998, Darren Cook wrote: > >Here's a site everybody should check out, if they haven't already seen it. > >It is possible to suck out all of Netscape's cached information, including > >credit card numbers (yup, it saves those!) without your knowing it. > > Credit card numbers is a bit of an exaggeration. "about:cache" only shows > URL's, which means it would only store form information if submitted with According to an article in Edupage, which can be found at sunsite SUT-- http://sunsite.sut.ac.jp/edupage/Edupage-98.09.29.html Netscape's flaw does NOT involve encrypted information, as this is not stored in cache. I suppose if you are ordering something through a non-secure site (not many of these are left, are there?), then there might be a risk. So far nobody has reported such an attack, as this flaw is still described as "hypothetical" by Netscape. Then again, Edupage is quoting USA Today, so YMMV by a lot here..... David Riley Hachinohe Institute of Technology 88-1, Myo, Ohbiraki Hachinohe-shi Aomori-ken http://w3.clat.hi-tech.ac.jp --------------------------------------------------------------- Next Meeting: 10 October, 12:30 Tokyo Station Yaesu central gate Featuring the IMASY Eng. Team on "IPv6 - The Next Generation IP" Next Nomikai: 20 November, 19:30 Tengu TokyoEkiMae 03-3275-3691 --------------------------------------------------------------- Sponsor: PHT, makers of TurboLinux http://www.pht.co.jp
- Follow-Ups:
- Re: tlug: Cache cow security hole
- From: Jonathan Byrne <jq@example.com>
Home | Main Index | Thread Index
- Prev by Date: Re: tlug: Cache cow security hole
- Next by Date: Re: tlug: Cache cow security hole
- Prev by thread: Re: tlug: Cache cow security hole
- Next by thread: Re: tlug: Cache cow security hole
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links