Re: Browser security questions

From: David Dorward (dorward_at_yahoo.com)
Date: 04/06/05


Date: Wed, 06 Apr 2005 19:19:39 +0100

General Schvantzkoph wrote:

> 1) Can a cookie that is generated by one website be read by another?
> Cookies are used to store all sorts of sensitive information, is it
> possible for a rogue website to search through the cookies on your system
> to find things like passwords?

Not in theory. Sometimes security problems are uncovered in browsers though.

> 2) What limits are placed on what Java and Java Script can access?. Can
> they read anything that is readable by the user or are they limited to a
> sandbox of some sort? Can they read the browser's passwords file? Can they
> read arbitrary cookies?

They are sandboxed, although Java Applets can request permission to access
things that are normally forbidden to them.

In a web context, JavaScript can access the current document, cookies for
the current host and other documents in frames or popups on the same host.

-- 
David Dorward       <http://blog.dorward.me.uk/>   <http://dorward.me.uk/>
                     Home is where the ~/.bashrc is


Relevant Pages

  • Re: Browser security questions
    ... > Cookies are used to store all sorts of sensitive information, ... > possible for a rogue website to search through the cookies on your system ... "Linux Network Security", the ultimate book on protecting your network from ...
    (comp.os.linux.security)
  • Re: Other methods for preventing "not have exclusive access at this time" message?
    ... That's it, I'm baking you cookies. ... I've been trying all sorts of ways to figure that out for about a year ... Chose "Modify" from the wizard and when it gets to the optional plug in page, ...
    (microsoft.public.access.security)
  • Re: Free Opera registration today
    ... >> And it set some interesting cookies, so I reckon they could well be ... >> different for each enquiry. ... > Hmm, maybe; although I've just looked at my cookies and there's nowt ... all sorts of different sorts of choccy chip baked in 'em. ...
    (uk.rec.sheds)
  • Re: User attached to other users session
    ... issue dealing with cookies for sites that are imbeded, ... hitting the back button sorts it... ...
    (microsoft.public.dotnet.framework.aspnet)
  • 3Ware 3DM denial of service attack
    ... response. ... Previously I didn't have a test case other than "run a nessus ... scan against the host". ... have ANY cookies sent. ...
    (Bugtraq)

Loading