Re: YANDEX cookie



On Mon, 9 Jan 2006 19:03:53 -0500, "Tom Leylan"
>"Fitz" <SENDNOMAIL@xxxxxxxxxxxxxxxxxx> wrote...

>> A cookie, in and by itself, is a text file and won't harm your computer
>> although they can be used to track your surfing habits..

That should be true, but is not. By DESIGN, a cookie can contain HTML
and scripts, and these scripts can be run.

This came to light when a bug was found, whereby a script dropped by
an Internet web site could be run in local HD "My Computer" security
zone, rather than in Internet security zone.

The patch fixed the bug by either forcing Internet Zone context on
such cookies, or maintaining the actual zone the script-in-cookie was
dropped from. The difference is material, if (say) you allow
Restricted Zone to drop cookies but didn't intend to run scripts.



>---------- ----- ---- --- -- - - - -
Don't pay malware vendors - boycott Sony
>---------- ----- ---- --- -- - - - -
.



Relevant Pages

  • Re: [FYI] XP SP2 Security BUG(s) Report
    ... >not just the scripts in posts or pages. ... This is not an SP2 bug, but an indication of poor design in IE and OE. ... Internet) are set to. ... now alerted on are running in local HD "My Computer" zone. ...
    (microsoft.public.windowsxp.general)
  • Re: [FYI] XP SP2 Security BUG(s) Report
    ... >not just the scripts in posts or pages. ... This is not an SP2 bug, but an indication of poor design in IE and OE. ... Internet) are set to. ... now alerted on are running in local HD "My Computer" zone. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: [FYI] XP SP2 Security BUG(s) Report
    ... >not just the scripts in posts or pages. ... This is not an SP2 bug, but an indication of poor design in IE and OE. ... Internet) are set to. ... now alerted on are running in local HD "My Computer" zone. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: After CoolwebSearch
    ... Lock down the "Internet" zone so scripts either require prompting before ... If you have a site that you trust to run scripts, ... sites zone. ...
    (microsoft.public.security.virus)
  • Re: Gates: Buy stamps to send e-mail
    ... >> the installed base of malware that looks up email addresses on the ... But it's still free to send if you hi-jack malware. ... - arbitrary web sites (scripts, ActiveX, install on demand) ... It's only when these are executed in "My Computer" zone ...
    (microsoft.public.windowsxp.general)