[39952] in bugtraq
Getting round website authentication with Firefox
daemon@ATHENA.MIT.EDU (account.throw@gmail.com)
Wed Jul 27 20:07:59 2005
Date: 24 Jul 2005 23:52:11 -0000
Message-ID: <20050724235211.29213.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: account.throw@gmail.com
To: bugtraq@securityfocus.com
Using firefox's "save target as" feature, you can get round web authentication.
Make a password protected directory (with a video file inside) (using .htaccess and htpasswd), check that it actully requires a login when you click the link to the video normally, then create a hyperlink to the file, right click save as - oh snap, it doesn't ask for authentication.
I've only tested it with a video file and Firefox 1.0.6.