Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Java applets access to internal DBs
From: blymn @ awadi . com . au (Brett Lymn)
Date: Mon, 30 Sep 1996 15:50:55 +0930 (CST)
To: genel @ inforamp . net (Gene Lee)
Cc: firewalls @ greatcircle . com
In-reply-to: <01BBAC84 . 6AB79FA0 @ genel> from "Gene Lee" at Sep 27, 96 02:58:59 pm

According to Gene Lee:
>
>on host-names. AFAIK, you cannot make a Java connection with any other 
>machine other than the one which served you the applet. Again, I may be 
>mistaken, others will surely confirm/clarify...
>

That is the way it is supposed to work.  The interesting thing is,
apparently, even after you have finished with the page the java thread
keeps running in your browser.  This means that you can have a java
thread running around doing all sorts of things without you knowing.
There is no real thread management in Netscape so you cannot tell what
is running.

Some people were suggesting a benign application for this (such as
factoring a large number or some such) but how long before someone
puts a password cracker thread onto your machine whilst you are
browsing www.hotpix.com????  I would think that with the right sort of
lure (and I think that free porn would do the trick nicely ;-) you
would get lots of unwitting volunteers giving you their cpu to use.

-- 
Brett Lymn, Computer Systems Administrator, AWA Defence Industries
===============================================================================
  "Upgrading your memory gives you MORE RAM!" - ad in MacWAREHOUSE catalogue.




References:
Indexed By Date Previous: Re: SOLARIS x86 as firewall platform?
From: bwalker @ musings . com (Brad Walker)
Next: Re: FW-1 - less secure ?
From: Jean-Francois Zwobada <zwobada @ apogee-com . fr>
Indexed By Thread Previous: RE: Java applets access to internal DBs
From: Gene Lee <genel @ inforamp . net>
Next: Re: Java applets access to internal DBs
From: Steve Gibbons <steve @ wyrm . AZTech . Net>

Google
 
Search Internet Search www.greatcircle.com