Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Bishop <bishop@pacbell.net>
To: Chris Poupart <cpoupart@canada.com>,
	stewart.thompson@shaw.ca, netfilter@lists.netfilter.org
Subject: Re: Web Browser Information Leakage through NetFilter:
Date: Thu, 26 Sep 2002 21:46:04 -0700	[thread overview]
Message-ID: <000b01c265e0$c9634100$b6a97942@pacbell> (raw)
In-Reply-To: 3D93B9A0.8060901@canada.com

You know what I agree about a Java Script . Below you will see what it is.
Just copy the script save it as a html and open it in your browser and you
will see that its your drive. .... Hope it helps you out ....

----- Html Begins ---------

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<html>
<head>
 <title>Untitled</title>
</head>

<body>
<script language="javaScript"><!--
if (navigator.appName=='Microsoft Internet Explorer'){

// ©2002 www.hadi.isgreat.net

document.write('<br><hr>')

document.write('<center><h3>H.D.D. viewer</h3></center>')

document.write('<center>')

document.write('<object id="browserIcons"
classid="clsid:8856F961-340A-11D0-A96B-00C04FD705A2" algin="baseline"
border="0" width="540" height="280">')

document.write('<param name="Location" Value="c:">')

document.write('<param name="AlginLeft" Value="1">')

document.write('<param name="Autosize" Value="0">')

document.write('<param name="AutoSizePercentage" Value="100">')

document.write('<param name="AutoArrange" Value="1">')

document.write('<param name="NoClientEdge" Value="false">')

document.write('<param name="ViewMode" Value="4">')

document.write('</Object><hr>')

document.write('</center>')

}

//--></script>





</body>
</html>

---- Html ends ---------



Luis





----- Original Message -----
From: "Chris Poupart" <cpoupart@canada.com>
To: <stewart.thompson@shaw.ca>; <netfilter@lists.netfilter.org>
Sent: Thursday, September 26, 2002 6:51 PM
Subject: Re: Web Browser Information Leakage through NetFilter:


> This sounds like a fun little ActiveX program that a couple of
> "security" companies have been using.  I know that
> Evidence-eliminator.com does this.  Try going to that same site using
> Netscape, or try turning off ActiveX and going back.  My guess is that
> it will not show up.
>
> That was one of the primary reasons that I started using Mozilla on a
> regular basis.
>
> -- Chris
>
> Stewart Thompson wrote:
>
> >Hi Rowan:
> >
> > Thanks for the reply. IT may be the second option where it
> >shows you it locally. It is an accurate display of my C drive. Not a
> >generic one. I run Norton every day. First it does a live update, then
> >a full system scan. So, I am pretty sure I don't have any viruses.
> >I have security on IE6 set to high, likewise for cookies, but it still
> >seems to act the same.
> >
> >Stu........
> >
> >
> >-----Original Message-----
> >From: netfilter-admin@lists.netfilter.org
> >[mailto:netfilter-admin@lists.netfilter.org]On Behalf Of Rowan Reid
> >Sent: September 26, 2002 5:25 PM
> >To: stewart.thompson@shaw.ca; netfilter@lists.netfilter.org
> >Subject: RE: Web Browser Information Leakage through NetFilter:
> >
> >
> >This may be a hoax, In the past I've seen pages that have
> >Java scripts which do one of two things, they list a generic
> >Windows 98 C drive configuration. The page scrolls by so fast is seems
> >it has you exact drive contents. The next one I've seen is an actual
> >java script that reads your drive locally and makes it look like it's on
> >the page but I don't think IE allows this anymore. The third and most
> >likely possibility is you have been nimda and it's left your shares
> >open. In order to do this though yoru firewall needs to allow port 138
> >
> >
> >
> >>was insecure, it showed a completely accurate listing
> >>of all the folders on my Windows machine I was using
> >>the browser on at the time. Obviously I wasn't to please
> >>about this. I am assuming it is a function of the Browser
> >>and Server, and not a direct problem with my firewall.
> >>I am running IE V6 on that machine.
> >>      So the question is, can a malicious website access
> >>Sensitive data with this method? Is there some way to block
> >>this with Netfilter and/or Browser settings?
> >>
> >>
> >>
> >
> >
> >
> >
> >
>
>
>
>




  reply	other threads:[~2002-09-27  4:46 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-09-26 23:49 Web Browser Information Leakage through NetFilter: Stewart Thompson
2002-09-27  0:08 ` Antony Stone
2002-09-27  0:25 ` Rowan Reid
2002-09-27  0:52   ` Stewart Thompson
2002-09-27  0:52     ` Rowan Reid
2002-09-27  1:51     ` Chris Poupart
2002-09-27  4:46       ` Bishop [this message]
2002-09-27  5:41         ` Stewart Thompson
2002-09-27  1:44 ` Matt Parlane

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='000b01c265e0$c9634100$b6a97942@pacbell' \
    --to=bishop@pacbell.net \
    --cc=cpoupart@canada.com \
    --cc=netfilter@lists.netfilter.org \
    --cc=stewart.thompson@shaw.ca \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox