[1893] in WWW Security List Archive

home help back first fref pref prev next nref lref last post

Re: how do I keep a browser from caching files

daemon@ATHENA.MIT.EDU (Jeff Weinstein)
Wed Apr 24 05:04:21 1996

Date: Tue, 23 Apr 1996 23:55:44 -0700
From: Jeff Weinstein <jsw@netscape.com>
Reply-To: jsw@netscape.com
To: Pete Shipley <shipley@dis.org>
CC: www-security <www-security@ns2.rutgers.edu>
Errors-To: owner-www-security@ns2.rutgers.edu

Pete Shipley wrote:
> 
> (Re: netscape)
> 
> >
> >   I would propose another (different) scheme. Usually, browsers do not cache
> }data
> >resulting from a POST operation.
> 
> take a look in the file fat.db located in you cache directory
> 
> >-+-+ Pierre-Yves BONNETAIN (aka Pyb)
> >     Consultant Internet
> 
> you will find all finds of fun stuff including passwords from old forms...

  This has been fixed in the latest Atlas beta, which is on the FTP site
now (sorry, mac version not coming until tomorrow).  Only passwords that
were entered into HTML forms were getting put into the fat.db file.  HTTP
authentication passwords are never written to disk.

	--Jeff

-- 
Jeff Weinstein - Electronic Munitions Specialist
Netscape Communication Corporation
jsw@netscape.com - http://home.netscape.com/people/jsw
Any opinions expressed above are mine.

home help back first fref pref prev next nref lref last post