| 
          
         | 
        
          
            <<  
             ^ 
              >>
          
          
            
              
                Date: 1999-02-25
                 
                 
                Klaut win.ini: Netscape 4.5 Exploit
                
                 
-.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- 
                 
                
      Unübliche Breaking News von Bennett Haselton, der  
gewöhnlich an der Zensurfront unterwegs ist. Sie handeln   
darüber, wie man vermittels Netscape 4.5 die win.ini &  
andere auch vom Pfade her bekannte Dateien von Festplatten  
fladern kann. 
 
post/scrypt: Breaking & unbestätigt. Wir ersuchen  
Interessierte höflich um Evaluation. 
 
-.-. --.-  -.-. --.-  -.-. --.-  -.-. --.-  -.-. --.-  -.-. --.-  
 
It is about a security hole that I found about a few hours ago,  
in Netscape Communicator 4.x.  The security hole allows  
you to view any file on a person's hard drive if they use  
Netscape Communicator for Windows. 
 
Of the different browser bugs that ever been found, bugs that  
allow you to read the contents of a person's hard drive are  
considered *by far* the most serious.  Only a handful have  
ever actually been discovered. 
 
The News.com article links to a page on Peacefire.org that  
demonstrates the security hole at  
http://www.peacefire.org/readfile/
                   
 
(Note: this is *not* the same as the security hole that I found  
in HotMail a few weeks ago, which you may have also gotten  
an e-mail about.) 
 
This is off the beaten path from the anti-Internet-censorship  
issues that Peacefire works on (and that I usually send out e- 
mails about), but I thought you might be interested since this  
story is less than an hour old. 
 
 
http://www.peacefire.org/readfile/
                   
 
	-Bennett  
 
 
-.-. --.-  -.-. --.-  -.-. --.-  -.-. --.-  -.-. --.-  -.-. --.-
    
                 
- -.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- 
                
edited by Harkank 
published on: 1999-02-25 
comments to office@quintessenz.at
                   
                  
                    subscribe Newsletter
                  
                   
                
- -.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- 
                
                  <<  
                   ^ 
                    >> 
                
                
               | 
             
           
         | 
         | 
        
          
         |