[32168] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Internet Explorer and Opera local zone restriction bypass

daemon@ATHENA.MIT.EDU (Heikki Toivonen)
Mon Oct 27 15:06:35 2003

Message-ID: <3F9D651E.40606@comcast.net>
Date: Mon, 27 Oct 2003 10:34:06 -0800
From: Heikki Toivonen <hjtoi@comcast.net>
MIME-Version: 1.0
To: bugtraq@securityfocus.com
In-Reply-To: <20031025100233.6289.qmail@linuxmail.org>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit

Mindwarper * wrote:
> If Mozilla or Opera are installed it is also possible to use they're data which is stored in the /Application Data/.
> The only problem is that I will still have to know the username of the victim.

Mozilla user's profile path will have a randomly named directory. See 
below (this on Windows 2000 and XP):

C:\Documents and Settings\<Windows username>\Application 
Data\Mozilla\Profiles\<profile name, usually default>\<random 8 
characters>.slt\

Older Mozilla installations may have slightly different path, but they 
should all still contain that "salted" directory name.

-- 
   Heikki Toivonen


home help back first fref pref prev next nref lref last post