Re: How does GMail know I use Firebug extension in Iceweasel?



On Nov 28, 2007 7:06 PM, Douglas A. Tutty <dtutty@xxxxxxxxxxxxx> wrote:

<snip>

AIUI, enabling JavaScript enables the remote site to run javascript on
your box. It doesn't do any sort of audit of what it will run. So I
would assume tht it can do whatever javascript is capable of.

Can javascript read my .ssh directory and grab my id_rsa or id_dsa?

Javascript the language can - i.e. you could write a script file in JS
instead of Perl. However, JS that is run in a web page is sandboxed.
If it could read your files it would be considered a (very) major security
flaw in that browser's JS implementation and the news would be all
over the tech sites.


Cheers,
Kelly Clowers


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • Re: risks of using net apps as a user in wheel or adm?
    ... Would it be better to have a separate user not a member of any special ... some risk having any user on a box run iceweasel, javascript, and flash? ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: howto: please wait, this may take a few seconds...
    ... AJAX libraries. ... creates a tag linking in a PHP-generated script file. ... You could also do it without Javascript. ...
    (comp.lang.php)
  • Re: Mouse position not working anymore
    ... I need to get the mouse cursor's position using JavaScript. ... of JavaScript code isn't working anymore. ... Go back to a version of your script file that works and apply your new ... error using *only* the positioning function. ...
    (comp.lang.javascript)
  • Re: firefox keeps grabbing huge chunks of my system
    ... Could be java or javascript running. ... what plugins are installed etc etc etc ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Javascript read web directory
    ... I need to make a javascript read a web directory from a remote site (ie ... (The remote die does not have an index.htm and does have directory ... and the method would get the directory listings and populate an array ...
    (comp.lang.javascript)