Enableing java logging in MSIE is dangerous

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



There is a feature  in the microsoft virtual machine shipped with
internet explorer called java logging (tools > internet options advanced)
what this basicly does is write java

System.out.println() ,  System.err.println etc output to a known
location on the users harddisk namely

%WINDIR%\java\javalog.txt

Those who have been following HTTP-EQUIV's discovery will realise that
this is extremely dangerous, as it will allow execution of arbitrary
code
However since this feature is disabled by default it can be considered
to be very low risk

--
  jelmer



[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux