[32168] in bugtraq
Re: Internet Explorer and Opera local zone restriction bypass
daemon@ATHENA.MIT.EDU (Heikki Toivonen)
Mon Oct 27 15:06:35 2003
Message-ID: <3F9D651E.40606@comcast.net>
Date: Mon, 27 Oct 2003 10:34:06 -0800
From: Heikki Toivonen <hjtoi@comcast.net>
MIME-Version: 1.0
To: bugtraq@securityfocus.com
In-Reply-To: <20031025100233.6289.qmail@linuxmail.org>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Mindwarper * wrote:
> If Mozilla or Opera are installed it is also possible to use they're data which is stored in the /Application Data/.
> The only problem is that I will still have to know the username of the victim.
Mozilla user's profile path will have a randomly named directory. See
below (this on Windows 2000 and XP):
C:\Documents and Settings\<Windows username>\Application
Data\Mozilla\Profiles\<profile name, usually default>\<random 8
characters>.slt\
Older Mozilla installations may have slightly different path, but they
should all still contain that "salted" directory name.
--
Heikki Toivonen