OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Derek Johnson (dqjbtinternet.com)
Date: Mon Nov 26 2001 - 00:54:48 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    ('binary' encoding is not supported, stored as-is) If a user sets the option

    "Prompt to allow cookies to be stored on your
    machine"

    I have found that this can be bypassed in ME by local
    Javascript code directly setting a cookie.

    A request to disable the storing of cookies is honored
    but not the option to prompt before storing them.

    Hence it is insecure to set this option with Javascript
    enabled. It is no known if this is fixed by any
    combination of patches issued by Microsoft.