[81703] in Cypherpunks
Re: Netscape Bug :)))
daemon@ATHENA.MIT.EDU (Martin Minow)
Fri Jun 13 01:30:09 1997
In-Reply-To: <199706130347.WAA08219@manifold.algebra.com>
Date: Thu, 12 Jun 1997 21:37:51 -0700
To: cypherpunks@Algebra.COM, ichudov@Algebra.COM (Igor Chudov @ home)
From: Martin Minow <minow@apple.com>
Reply-To: Martin Minow <minow@apple.com>
>William H. Geiger III wrote:
>> Seems that there is a bug in Netscape including the new Communicator that
>> will allow a web site to read *ANY* file on your computer. I repeate
>> *ANY*, yes Virginia, *ANY* file on your computer.
>
>And what is the exploit?
>
According to an uninformitive, but extensive, report on CNN, the firm
is being very closed-mouth about the bug, and expects to be richly
rewarded "The $1000 bug reward was an insult." They will, however,
*give* the information to Netscape if they appear in person at the
company offices in Aarhus.
You might want to look at PC Lab's web site (or PC Magazine, I don't
remember which). All of the examples appeared to use Windows, and
the words "Active X" and "Java" were not used.
Martin Minow