OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: IE 5 & JavaScript
From: sigippWELLA.COM.BR
Date: Thu May 25 2000 - 09:24:07 CDT


Hi,

I recently visited a site for checking, what informations my browser resp. our
proxy sends to any server. So i visited

http://privacy.net/analyze

Well, i have execution of scripts configured to "confirm". So i expected some
dialogue to confirm. But nothing. And the site echoed me back some informations,
like my screen resolution. And it said, that VBScript and JavaScript where
enabled and running. So i disabled scripting completely, and now it seemed that
there are none of these informations sent to the server.

So now: Is it possible that IE5 still executes some script without confirmation
dialogue? If yes, does anyone know, what scripts are executed without
confirmation? And if yes, i think, this would be exploitable.

Greetings
Siegfried Gipp