Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: [Full-disclosure] Firefox + popup blocker + XMLHttpRequest + srand() = oops Feb 05 2007 12:38PM
pdp (architect) (pdp gnucitizen googlemail com)
Hi Michal,

Nice read! Very complicated though and with too many "If"s, but very
interesting. I just want to sum up. As long as the user has a
malicious html file stored on their system you know the path to it,
the attacker can read local files. You don't need to do this pop-up
trick at all. You may...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus