Re: Microsoft IE cookies readable via about: URLS

From: Kristian Strickland (strikri@co-opsonline.com)
Date: 11/13/01


From: "Kristian Strickland" <strikri@co-opsonline.com>
To: <bugtraq@securityfocus.com>
Date: Tue, 13 Nov 2001 15:33:59 -0400
Subject: Re: Microsoft IE cookies readable via about: URLS
Message-ID: <3BF13D67.22367.26B691@localhost>


> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
> Settings\ZoneMap\ProtocolDefaults\about = 4

I am not able to reproduce this workaround.

During our brief conversation after his original post, I indicated to Andrew that
I use Win95 4.00.950 B and IE 5 5.50.4522.1800. No matter which value, 1
through 4 , that I use, I am unable to get about URLs in anything other than the
Internet Zone. This includes setting the value to 4 and rebooting.

--Kristian

Kristian Strickland, BSc CS (StFX '94)
System Support Specialist, AIX & OpenVMS
Co-op Atlantic, Moncton NB, Canada

Please R.U.N.S.A.F.E.
http://www.jmu.edu/computing/info-security/engineering/runsafe.shtml