Browser security questions

From: General Schvantzkoph (schvantzkoph_at_yahoo.com)
Date: 04/06/05


Date: Wed, 06 Apr 2005 09:17:28 -0400

I have a few questions about web browsers.

1) Can a cookie that is generated by one website be read by another?
Cookies are used to store all sorts of sensitive information, is it
possible for a rogue website to search through the cookies on your system
to find things like passwords?

2) What limits are placed on what Java and Java Script can access?. Can
they read anything that is readable by the user or are they limited to a
sandbox of some sort? Can they read the browser's passwords file? Can they
read arbitrary cookies?

Thanks



Relevant Pages

  • Re: Beware of IRSs cookie
    ... Below is IRS's story on the cookies: ... IRS Privacy Policy ... You have entered the Internal Revenue Service's website, ... We will not collect personal information about you just because you visit ...
    (misc.taxes)
  • Privacy slip on official US sites
    ... The White House and National Security Agency have been caught tracking visitors ... Although widely used on commercial websites, US federal guidelines prohibit ... Cyber rights activists said cookies could be used to track surfing habits. ... "persistent cookies" to log who visits its website. ...
    (alt.privacy)
  • Privacy slip on official US sites
    ... Although widely used on commercial websites, US federal guidelines prohibit ... Cyber rights activists said cookies could be used to track surfing habits. ... "persistent cookies" to log who visits its website. ... At the same time the White House website was found to be using a combination ...
    (alt.politics.bush)
  • Re: "PC Flank" Browser Test firewall checker
    ... Cookies are frequently used by advertiser sites in conjunction ... with provider sitesto track you as a specific person. ... if you came from Fortune Magazine's website, ...
    (comp.os.linux.networking)
  • Re: is it a cookie? how to delete privous typed information?
    ... The web site's Shopping Bag session appears to be IP-based. ... >> What is the website and URL in question, ... >>> up the cookies folder everyday. ... >>> I have tried to delete all the cookies and temporary internet files ...
    (microsoft.public.windows.inetexplorer.ie6.browser)

Loading