More Netscape Passwords Available.

From: Rob Jones (robert.e.jonesat_private)
Date: Tue Dec 21 1999 - 19:58:52 PST

  • Next message: Richard Sather: "Re: GroupeWise Web Interface"

    --------------DEDED72A44B2CEF304F6075F
    Content-Type: text/plain; charset=us-ascii
    Content-Transfer-Encoding: 7bit
    
    Netscape 4.7 stores passwords in preferences.js even
    if you never ever even once tell it 'remember passwords',
    and even if its a fresh install of 4.7 (the solaris install I tested
    on has never seen any other version of Netscape).
    
    I thought I was loosing it with people pointing out that this didnt work
    when I thought it did but I've done my howework thistime and
    this bug does definitely affect
    
        Solaris 2.5 Netscape 4.7
        Redhat Linux 6.0 Netscape 4.7
    
    However it only stores them in the file from the time you log onto
    your mail server to the time you quite and close all netscape windows.
    
    Obviously this isnt as bad as it could be but it does mean there is a
    window of opportunity for a hacker to grab your password
    from this file. Like sending you a mail, saying check out this attachment.
    You will have had to type in your password (its then in the file), and
    the application you run can grab your password .... The rest is obvious.
    
    Rob
    
    P.S. This was tested with an IMAP rather than POP server, but I doubt
    if its any different.
    
    P.P.S. No I've not contacted Netscape yet. If anyone thinks they would
    change this then please email them. I've havent got time because I
    leave this job (peranantly, not just for christmas) on Friday and
    I have too much to do before then to find the right  person to contact.
    
    
    --------------DEDED72A44B2CEF304F6075F
    Content-Type: text/html; charset=us-ascii
    Content-Transfer-Encoding: 7bit
    
    <!doctype html public "-//w3c//dtd html 4.0 transitional//en">
    <html>
    Netscape <b>4.7 </b>stores passwords in preferences.js even
    <br>if you never ever even once tell it 'remember passwords',
    <br>and even if its a fresh install of 4.7 (the solaris install I&nbsp;tested
    <br>on has never seen any other version of Netscape).
    <p>I thought I&nbsp;was loosing it with people pointing out that this didnt
    work
    <br>when I&nbsp;thought it did but I've done my howework thistime and
    <br>this bug does definitely affect
    <p>&nbsp;&nbsp;&nbsp; Solaris 2.5 Netscape 4.7
    <br>&nbsp;&nbsp;&nbsp; Redhat Linux 6.0 Netscape 4.7
    <p>However it only stores them in the file from the time you log onto
    <br>your mail server to the time you quite and close all netscape windows.
    <p>Obviously this isnt as bad as it could be but it does mean there is
    a
    <br>window of opportunity for a hacker to grab your password
    <br>from this file. Like sending you a mail, saying check out this attachment.
    <br>You will have had to type in your password (its then in the file),
    and
    <br>the application you run can grab your password .... The rest is obvious.
    <p>Rob
    <p>P.S. This was tested with an IMAP rather than POP&nbsp;server, but I
    doubt
    <br>if its any different.
    <p>P.P.S. No I've not contacted Netscape yet. If anyone thinks they would
    <br>change this then please email them. I've havent got time because I
    <br>leave this job (peranantly, not just for christmas) on Friday and
    <br>I have too much to do before then to find the right&nbsp; person to
    contact.
    <br>&nbsp;</html>
    
    --------------DEDED72A44B2CEF304F6075F--
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:22:40 PDT