Re: Netscape Communicator 4.5 can read local files

From: Todd C. Campbell (toddcat_private-LINK.NET)
Date: Mon Nov 30 1998 - 07:29:59 PST

  • Next message: Yuri Kuzmenko: "Re: RedHat 5.2 lrzsz-0.12.14-5 have serious security hole"

    Trev wrote:
    
    > At 12:48 PM 11/25/98 -0500, Ben Collins wrote:
    > >If some one here can setup a webpage, send me the URL, have that page read
    > >the file '/test.txt' from my hardrive and then that person send the
    > >contents to this list, I will believe. Otherwise I think this whole
    > >hysteria over 'unforseen' dangers should stop.
    >
    > I've whipped up a couple of demos of this bug that send the contents to a
    > cgi.  There is a windows version that I know works, and a unix version I
    > can't test because my linux box is down (it's a hardware thing).  This is
    > for anyone who has doubts....
    >
    > http://www.kics.bc.ca/~trev/cgi-bin/test.html (Windoze)
    >
    > http://www.kics.bc.ca/~trev/cgi-bin/test-unix.html (UNIX)
    >
    > And yes, it can email it to you if you like :)
    >
    > Trev
    
    
    Does anybody know what Netscape's stance is on this, do they have a timeline?
    
    -Todd
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:24:24 PDT