Vulnerability Development mailing list archives

IE 5 & JavaScript


From: sigipp () WELLA COM BR (sigipp () WELLA COM BR)
Date: Thu, 25 May 2000 11:24:07 -0300


Hi,

I recently visited a site for checking, what informations my browser resp. our
proxy sends to any server. So i visited

http://privacy.net/analyze

Well, i have execution of scripts configured to "confirm". So i expected some
dialogue to confirm. But nothing. And the site echoed me back some informations,
like my screen resolution. And it said, that VBScript and JavaScript where
enabled and running. So i disabled scripting completely, and now it seemed that
there are none of these informations sent to the server.

So now: Is it possible that IE5 still executes some script without confirmation
dialogue? If yes, does anyone know, what scripts are executed without
confirmation? And if yes, i think, this would be exploitable.

Greetings
Siegfried Gipp


Current thread: