KaZaA - Bad Zone

From: David Krum (bugtraqat_private)
Date: Tue Jan 07 2003 - 10:53:05 PST

  • Next message: FreeBSD Security Advisories: "FreeBSD Security Advisory FreeBSD-SA-02:44.filedesc"

    To follow up my mid Oct post:
    
    KaZaA is still launching ads in the local zone.  KaZaA was contacted 6 Jan
    03 via their bug report page.
    
    "Pop-up ads are being spawned from the local hard disk.  This puts them in
    the local zone.  Scripts running in this zone can be harmful."
    
    I am now awaiting their response.
    
    To immunize KaZaA from this defect I have removed the permissions from the
    directory it launches ads from.  This has a nice side effect of not showing
    ads.  The directory to secure is:  %WinDir%\AdCache
    
    David
    



    This archive was generated by hypermail 2b30 : Tue Jan 07 2003 - 17:56:17 PST