Bugtraq mailing list archives
Bookmarks security vulnerabilities in both Internet Explorer 5.0
From: joro () NAT BG (Georgi Guninski)
Date: Sun, 9 May 1999 17:34:10 +0300
There is a design flaw in both Internet Explorer 5.0 and Netscape Communicator 4.51 Win95 (guess all 4.x versions of both browsers are vulnerable too) in the way they handle bookmarks. The problem arises if the user bookmarks (adds to favorites) and later chooses a specially designed "javascript:" URL. When the bookmark is chosen later, the JavaScript code in it is executed in the context (the same domain and protocol) of the document opened prior to choosing the bookmark. So, the JavaScript code has access to documents in the same domain. An interesting case is choosing the bookmark when the active document is a local file (the protocol is "file:") - then the JavaScript code has access to local files and directories. The vulnerabilities are more serious for Internet Explorer 5.0. Some of the vulnerabilities are: For Internet Explorer 5.0: Reading local files if the filename is known; Reading files in the domain of the active document (even if the web server is blocked by a firewall); Reading links in the active document and in documents in the same domain; Web spoofing of documents in the domain of the active document; Demonstration is available at: http://www.nat.bg/~joro/favorites.html For Netscape Communcator 4.51: Browsing local directories; Reading local files in the directory of the active document; Reading links in the active document and in documents in the same domain; Web spoofing of documents in the domain of the active document; Demonstration is available at: http://www.nat.bg/~joro/bookmarks.html Workaround: Disable JavaScript or do not bookmark untrusted pages Georgi Guninski http://www.nat.bg/~joro http://www.whitehats.com/guninski
Current thread:
- Re: [linux-security] OpenLinux 2.2: LISA install leaves root, (continued)
- Re: [linux-security] OpenLinux 2.2: LISA install leaves root Ralf Flaxa (May 09)
- SunOS 5.7 rmmount, no nosuid. Jonas Stahre (May 10)
- Re: SunOS 5.7 rmmount, no nosuid. C.J. Oster (May 10)
- nidsbench announcement Dug Song (May 13)
- Adminisrivia Aleph One (May 10)
- [BIND-BUGS #18] Non-delegated master domains Ian Carr-de Avelon (May 10)
- Re: [BIND-BUGS #18] Non-delegated master domains Andrew Brown (May 11)
- Re: [BIND-BUGS #18] Non-delegated master domains Dan Busarow (May 11)
- ICQ Password Revealer Dmitri Alperovitch (May 10)
- Re: Adminisrivia Brian Fisk (May 10)
- Bookmarks security vulnerabilities in both Internet Explorer 5.0 Georgi Guninski (May 09)
