OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Christopher G. Lewis (Chris_at_ChristopherLewis.com)
Date: Tue Aug 06 2002 - 15:21:48 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Jelmer -

    > Bypassing cookie restrictions in IE 5+6
    >
    > Description
      <snip>
    > This behaviour completely ignores the privacy settings and allows
    > website owners and advertisers to start tracking your every move once
    > again.
      <snip>
    > Workaround:
    >
    > disable active scripting

    If you turn off userdata persistence in the security zone, you can
    completely turn off userdata.
    Tools|Internet Options
      Security Tab
      Custom Level Button
        <last option in Miscellaneous>
        Userdata persistence
          <set to>Disable

    But yes, MS should use the "Per-Site Privacy Actions" that are available
    with cookies for UserData

    Chris

    > -----Original Message-----
    > From: Jelmer [mailto:jelmerkuperus.xs4all.nl]
    > Sent: Saturday, August 03, 2002 8:43 PM
    > To: bugtraqsecurityfocus.com; securemicrosoft.com
    > Subject: Bypassing cookie restrictions in IE 5+6