Thursday, November 15, 2001
Wednesday, November 14, 2001
Tuesday, November 13, 2001
Monday, November 12, 2001
Sunday, November 11, 2001
Saturday, November 10, 2001
Cookie Data in IE Can Be Exposed or Altered Through Script Injection
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms01-055.asp Originally posted: November 08, 2001 Who should read this bulletin: Customers using Microsoft� Internet Explorer Impact of vulnerability: Exposure and altering of data in cookies. Maximum Severity Rating: High Recommendation: Customers should consider disabling active scripting in the Internet Zone and the Intranet Zone. Customers using Outlook Express who have not set OE to use the "Restricted Sites" Zone should do so as a best practice. Affected Software: * Microsoft Internet Explorer 5.5 * Microsoft Internet Explorer 6.0 Technical description: Web sites use cookies as a way to store information on a user's local system. Most often, this information is used for customizing and retaining a site's setting for a user across multiple sessions. By design each site should maintain its own cookies on a user's machine and be able to access only those cookies. A vulnerability exists because it is possible to craft a URL that can allow sites to gain unauthorized access to user�s cookies and potentially modify the values contained in them. Because some web sites store sensitive information in a user�s cookies, it is also possible that personal information could be exposed. Microsoft is preparing a patch for this issue, but in the meantime customers can protect their systems by disabling active scripting. (The FAQ provides step-by-step instructions for doing this). This will protect against both the web-hosted and the mail-borne variants discussed above. When the patch is complete, Microsoft will re-release this bulletin and provide details on obtaining and using it.
Internet Servers Intranet Servers Client Systems
Internet Explorer 5.5 High High High
Internet Explorer 6.0 High High High
To disable: * On the Tools menu, click Internet Options, click the Security tab, and then click Custom Level. * In the Settings box, scroll down to the Scripting section, and click Disable under "Active scripting" and "Scripting of Java applets". * Click OK, and then click OK again. All blogdialers know that the buttons used to post here in IE use active scripting, so once you turn it off you will have to use Mozilla http://www.mozila.org or another browser to post, or, enable active scripting just when youre here. Its amazing isnt it? Sites will be able to get your cookies, look into your shit and fuck with your identity. Like I said before, I dont have a problem with companies getting big and people getting rich, but I do have a problem with people and companies who thirsto for world domination (without good reason :] )