Subject: HotJava Browser 3.0 JavaScript security vulnerability
From: Georgi Guninski (guninskiGUNINSKI.COM)
Date: Wed Oct 25 2000 - 11:44:38 CDT

Georgi Guninski security advisory #25, 2000

HotJava Browser 3.0 JavaScript security vulnerability

Systems affected:
HotJava Browser 3.0, Windows98 - probably other platforms since the
browser is written in Java.

Risk: High
Date: 25 October 2000

There is a security vulnerability in HotJava Browser 3.0 which allows
accessing the DOM of arbitrary URLs after viewing a web page.
This allows stealing of cookies.

The problem is opening an javascript: URL in a named window, which
accessing the DOM of the document in the named window.

The code is:
setTimeout("window.open('javascript:alert(\"The first link is:
\"+document.links[0].href);alert(\"The cookie is:

Disable JavaScript

Vendor status:
Sun was notified by email at least 4 days ago but did not hear back from

Georgi Guninski