ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Netscape flaw exposes users' hard drives

Matthew Broersma ZDNet.co.uk

Published: 01 May 2002 11:29 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An Israeli software firm has discovered a flaw in Netscape and Mozilla software that allows code hidden in a Web page to read files from the user's PC. The bug is a more serious variant of one patched in Microsoft's Internet Explorer in February.

GreyMagic Software on Monday reported that the problem affects XMLHttpRequest, which allows Web pages in the browser to send and receive XML data via HTTP, the standard Web transfer protocol. XML is an Internet language for describing just about any sort of data.

According to the report, verified by other developers, XMLHttpRequest doesn't properly check the security settings for some types of data requests in a Web page, allowing them, if properly disguised, to request data from the user's hard drive. The Internet Explorer bug required an attacker to know the name of a file on the user's PC in order to exploit that file, but the Mozilla bug also allows the contents of directories on the local drive to be listed.

GreyMagic created a demonstration of the bug that allows a Web page to display a window for exploring the viewer's own hard drive.

The bug is found in versions of Mozilla from 0.9.7 to 0.9.9 on various operating system platforms, and in Netscape versions 6.1 and higher. The flaw doesn't affect Mozilla 1.0 release candidate 1 because XMLHttpRequest appears to be broken in that release, according to Mozilla developers.

A patch for the bug was not available as of late morning on Wednesday.

GreyMagic also criticised Netscape's system for reporting bugs, saying a 24 April attempt to report the bug was not acknowledged. Following the firm's public report of the bug, another developer reported the bug to Mozilla's bug-tracking system, whose developers have confirmed the flaw. The flaw has also been distributed on the BugTraq security mailing list.

Netscape, a division of AOL Time Warner, uses Mozilla technology in its commercial browser. Mozilla itself is open source, meaning that its original programming code is freely available for alteration and re-distribution so long as any software that uses it is made available under the same terms. Mozilla software is used in other open-source browsers, such as the Galeon browser for Linux.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
58 out of 98 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Security Consultant Ethical Hacking / Penetration Testing - London

Job Title: Security Consultant Ethical Hacking / Penetration Testing Location: London Salary: Competitive Job Type: Permanent NET2S is an ...

Front End Developer XHTML, CSS, Javascript, W3C

The successful candidate will need to: -Use information/interaction design skills to develop and document site structures, navigation flows, wire ...

PHP developer (West Mids)

Candidates need to be solutions driven and poses the ability to recognise and solve incompatibility issues and bugs. A clear understanding and ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains