|
|||||||
|
You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community today, you will have fewer ads, access to post topics, communicate privately with other members, respond to polls, upload content and access many other special features. If you have any problems with the registration process or your account login, please contact us. Hint: Don't have time to visit us daily? Subscribe to our main RSS feed to receive our frontpage posts at your convenience. |
| Lounge Friendly banter and discussions unrelated to e-books |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
|
|
#1 |
|
Fully Converged
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
Posts: 12,179
Karma: 68037
Join Date: Oct 2002
Location: Switzerland
Device: Sony Portable Reader
|
Serious exploit in Greasemonkey 0.4
If you are using the wonderful Greasemonkey extension for Firefox, better disable it ASAP and then check out this link:
In other words, running a Greasemonkey script on a site can expose the contents of every file on your local hard drive to that site. Running a Greasemonkey script with "@include *" (which, BTW, is the default if no parameter is specified) can expose the contents of every file on your local hard drive to every site you visit. And, because GM_xmlhttpRequest can use POST as well as GET, an attacker can quietly send this information anywhere in the world.
__________________
Follow MR on Twitter |
|
|
|
|
|
#2 |
|
Evangelist
![]() ![]() ![]()
Posts: 418
Karma: 281
Join Date: Jul 2004
Location: Canada
Device: Assorted older devices
|
0.4? The greasemonkey website you linked to lists the most recent version at 0.3.3. Did they pull 0.4 when this vulnerability was found?
|
|
|
|
|
|
#3 |
|
Fully Converged
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
Posts: 12,179
Karma: 68037
Join Date: Oct 2002
Location: Switzerland
Device: Sony Portable Reader
|
__________________
Follow MR on Twitter |
|
|
|
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| PalmOne not serious about growth market China? | Colin Dunstan | Handhelds and Smartphones | 4 | 08-24-2009 12:12 PM |
| Serious Bugs in T5 Software | Bob Russell | Handhelds and Smartphones | 9 | 10-27-2004 01:47 AM |
| HandStory and Tungsten T3: serious problem with categories | BasilC | Reading Software | 6 | 09-04-2004 03:49 PM |