[16105] in bugtraq
Dangerous Java/Netscape Security Hole
daemon@ATHENA.MIT.EDU (Dan Brumleve)
Mon Aug 7 04:59:55 2000
Message-Id: <20000805020429.11774.qmail@securityfocus.com>
Date: Sat, 5 Aug 2000 02:04:29 -0000
Reply-To: Dan Brumleve <dan+security@BRUMLEVE.COM>
From: Dan Brumleve <dan+security@BRUMLEVE.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
Dear BugTraq,
I've found some security holes in Java and Netscape
that allow arbitrary network access and read-access
for local files and directories. As a demonstration
I've written Brown Orifice HTTPD, a web server and file
sharing tool that runs in Netscape Communicator on all
tested platforms. For more information, see:
http://www.brumleve.com/BrownOrifice
--
Dan Brumleve <dan+security@brumleve.com>