Re: Microsoft IE cookies readable via about: URLS
From: Kristian Strickland (strikri@co-opsonline.com)Date: 11/13/01
- Previous message: Michael Stone: "[SECURITY] [DSA 086-1] New versions of ssh-nonfree & ssh-socks fix buffer overflow"
- In reply to: Clover Andrew: "Re: Microsoft IE cookies readable via about: URLS"
- Next in thread: Oliver Petruzel: "RE: Microsoft IE cookies readable via about: URLS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Kristian Strickland" <strikri@co-opsonline.com> To: <bugtraq@securityfocus.com> Date: Tue, 13 Nov 2001 15:33:59 -0400 Subject: Re: Microsoft IE cookies readable via about: URLS Message-ID: <3BF13D67.22367.26B691@localhost>
> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
> Settings\ZoneMap\ProtocolDefaults\about = 4
I am not able to reproduce this workaround.
During our brief conversation after his original post, I indicated to Andrew that
I use Win95 4.00.950 B and IE 5 5.50.4522.1800. No matter which value, 1
through 4 , that I use, I am unable to get about URLs in anything other than the
Internet Zone. This includes setting the value to 4 and rebooting.
--Kristian
Kristian Strickland, BSc CS (StFX '94)
System Support Specialist, AIX & OpenVMS
Co-op Atlantic, Moncton NB, Canada
Please R.U.N.S.A.F.E.
http://www.jmu.edu/computing/info-security/engineering/runsafe.shtml
- Previous message: Michael Stone: "[SECURITY] [DSA 086-1] New versions of ssh-nonfree & ssh-socks fix buffer overflow"
- In reply to: Clover Andrew: "Re: Microsoft IE cookies readable via about: URLS"
- Next in thread: Oliver Petruzel: "RE: Microsoft IE cookies readable via about: URLS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|