Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: IE 5.0 vulnerability

IE 5.0 vulnerability

From: Josh Burns <jburns_at_BITSTREAMNETWORKS.COM>
Date: Fri, 22 Oct 1999 17:20:21 -0400

I'm not sure if this has been announced yet, but here goes.. I am not sure if this is an IE 5 problem, or not, but when you have cookies enabled (default setting), and you use a service like AOLMail, Hotmail, or anything that requires a name and password, it is stored in a cookie for later use. If the user closes IE, and then reopens it, and goes to the same page, and type in the first letter of their login name, a drop-down box will come up, with their user name in it, and you can click it. Then, if the user clicks on the password field, it automatically fills in their password. I'm not sure what the cookie for this looks like, if the stored password is encrypted, or not, because I didn't have time to test. This can most likely be fixed by going to Internet Options, and turning off cookies from all hosts. Please give me some feedback on this.

Josh Burns

<!-- body="end" -->
<HR>

<UL>
<LI><STRONG>Next message:</STRONG> Blue Boar: "Administrivia #2808"
<LI><STRONG>Previous message:</STRONG> Ofir Arkin: "Re: Classes?"
<LI><STRONG>Next in thread:</STRONG> Blue Boar: "Re: IE 5.0 vulnerability"
<LI><STRONG>Reply:</STRONG> Blue Boar: "Re: IE 5.0 vulnerability"
<LI><STRONG>Reply:</STRONG> David Schwartz: "Re: IE 5.0 vulnerability"
<LI><STRONG>Reply:</STRONG> David U.: "Re: IE 5.0 vulnerability"
<LI><STRONG>Reply:</STRONG> Josh Burns: "Re: IE 5.0 vulnerability"
<LI><STRONG>Reply:</STRONG> Mike Malouf: "Re: IE 5.0 vulnerability"
<LI><STRONG>Reply:</STRONG> -wb: "Re: IE 5.0 vulnerability"
</UL>
<HR>

<SMALL>

This archive was generated by hypermail 2.0b3
on Sun Oct 24 1999 - 12:29:32 CDT</EM>
</EM>
</SMALL>
</BODY>
</HTML>
Received on Oct 24 1999

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos