|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: Hotmail security hole - injecting JavaScript using <IMG
Subject: Re: Hotmail security hole - injecting JavaScript using
From: Metal Hurlant (metal_hurlant
YAHOO.COM)
Date: Wed Jan 05 2000 - 04:37:49 CST
- Next message: David Malone: "Re: Flaw in 3c59x.c or in Kernel?"
- Previous message: Wietse Venema: "Re: Symlinks and Cryogenic Sleep"
- In reply to: Kevin Hecht: "Re: Hotmail security hole - injecting JavaScript using <IMG"
- Next in thread: Dustin Miller: "Re: Hotmail security hole - injecting JavaScript using <IMG"
- Next in thread: ck
RIB.DE: "Re: Hotmail security hole - injecting JavaScript using <IMG"
- Reply: Metal Hurlant: "Re: Hotmail security hole - injecting JavaScript using <IMG"
- Reply: Dustin Miller: "Re: Hotmail security hole - injecting JavaScript using <IMG"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Tue, 04 Jan 2000, Kevin Hecht wrote:
> While Hotmail obviously has a filtering hole, should the browser
> manufacturers be on the hook here as well, given that javascript: URLs
> probably shouldn't be rendered at all by the <IMG> tag? While a
> JavaScript script may load an image on its own, I don't see why the
> script itself should be loaded and parsed from an <IMG> tag.
Netscape actually tries to parse the value returned by the script, so if your
script returns, for example, a valid XPM string, you'll get that image
displayed.
What could be useful would be a tag working like
<blockscript key=randompieceofdata>
</blockscript key=samepieceofdata>
anything between these tags would still get parsed as HTML, but with no script
hook working.
That way, filtering scripts out of untrusted HTML would become the browser
manufacturers responbility, and things would be a lot easier for everyone else.
Just dreaming,
Henri Torgemane
- Next message: David Malone: "Re: Flaw in 3c59x.c or in Kernel?"
- Previous message: Wietse Venema: "Re: Symlinks and Cryogenic Sleep"
- In reply to: Kevin Hecht: "Re: Hotmail security hole - injecting JavaScript using <IMG"
- Next in thread: Dustin Miller: "Re: Hotmail security hole - injecting JavaScript using <IMG"
- Next in thread: ck
RIB.DE: "Re: Hotmail security hole - injecting JavaScript using <IMG"
- Reply: Metal Hurlant: "Re: Hotmail security hole - injecting JavaScript using <IMG"
- Reply: Dustin Miller: "Re: Hotmail security hole - injecting JavaScript using <IMG"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
This archive was generated by hypermail 2b27 : Wed Jan 05 2000 - 13:32:36 CST