Great Circle Associates Firewalls
(April 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: BoS: Netscape2.0 sends mail to the world without authority
From: Mike Shaver <shaver @ neon . ingenia . com>
Date: Sun, 28 Apr 1996 21:58:51 -0400 (EDT)
To: brendan @ netscape . com (Brendan Eich)
Cc: sengle @ hti . net, firewalls @ greatcircle . com
In-reply-to: <3183F6AA . 15FB @ atm . mcom . com> from "Brendan Eich" at Apr 28, 96 03:52:26 pm

Thus spake Brendan Eich:
> Not only are mailto: and news: URL methods verboten for form.submit()
> auto-submission via JavaScript, but Netscape 3.0 puts up a confirming
> dialog whenever a mailto: post-method form is submitted -- even without
> JavaScript, an HTML form could claim it was doing something benign when
> it was really sending mail.  Users were one click away from losing their
> email addresses already.

Also, it was possible to get someone's email address up until 3.0 via
other means.  If one were to include an inline image with the URL:
ftp://ftp.com.net/my.gif, the browser would send the email address as
part of the FTP login, which could then be retrieved from the logs.
Atlas has a button to disable sending email address as password for
anonymous FTP.  Do MSIE or Mosaic or Lynx or ...?

Mike

-- 
#> Mike Shaver (shaver @
 ingenia .
 com)      Information Warfare Division  <#
#> Chief Tactical and Strategic Officer         "Saepe fidelis"        <#
#>                                                                     <#
#> "I like your game, but we have to change the rules." -- Anon        <#
#>                                                                     <#


References:
Indexed By Date Previous: Re: destruktiv hackers[D
From: mike @ fionn . lbl . gov (Michael Helm)
Next: Re: Q on using "netpipes" for firewall maintanance tasks
From: Darren Reed <avalon @ coombs . anu . edu . au>
Indexed By Thread Previous: Re: BoS: Netscape2.0 sends mail to the world without authority
From: Brendan Eich <brendan @ netscape . com>
Next: Re: BoS: Netscape2.0 sends mail to the world without authority
From: Jeff Fay <fay @ bliss . stetson . edu>

Google
 
Search Internet Search www.greatcircle.com