Re: Security Flaw: Any website can read your clipboard text

From: Art (null_at_zilch.com)
Date: 09/18/05


Date: Sun, 18 Sep 2005 18:01:14 GMT

On 18 Sep 2005 08:07:05 -0700, sudarmuthu@gmail.com wrote:

>Web sites you visit can retrieve data from your clipboard depending on
>your security settings. Go to this page (www.clipboard.googlemyway.com)
>and see if anything shows up in the box. If you are using Firefox or
>Opera you probably won't see anything. However, if you are using
>Internet Explorer then chances are that whatever you last copied into
>your clipboard will be displayed.
>
>It is working even under my Firewall. Seems to be a very major security
>flaw.

Don't expect firewalls to compensate for improper IE security
settings. Read the info at the url you gave. It tells you how to
set IE so the clipboard can't be read by web sites.

Art

http://home.epix.net/~artnpeg



Relevant Pages

  • Re: Unable to download/run ActiveX controls
    ... Your current security settings prohibit running Active X ... Test Your ActiveX Installation ... change the security settings for this zone? ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: SP2 & IE & Download
    ... Uninstall the firewall in you AV ... Your current security settings prohibit running Active X ... change the security settings for this zone? ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Big Security Permission Mistake - Please Help if You Can
    ... Reset Security Settings Back to the Defaults ... security template to be applied. ...
    (microsoft.public.windowsxp.configuration_manage)
  • Re: why microsoft choose mfc rather than wtl?
    ... One is that users need to keep their browser security settings as high as ... attacks that aren't possible in the higher security settings. ... point was that you should not dictate securiy settings to your customers ...
    (microsoft.public.vc.mfc)
  • RE: System Restore
    ... Security setting descriptionsComputer Configuration\Windows ... Windows XP Service Pack 2 introduces some security-enhancing changes to ... Account Policies Password Policy, Account Lockout Policy, and Kerberos Policy ... You can configure the security settings that are described in this section ...
    (microsoft.public.windowsxp.general)

Loading