Bugtraq mailing list archives

Enableing java logging in MSIE is dangerous


From: "Jelmer" <jelmer () kuperus xs4all nl>
Date: Sat, 17 Aug 2002 20:30:40 +0200

There is a feature  in the microsoft virtual machine shipped with
internet explorer called java logging (tools > internet options advanced)
what this basicly does is write java

System.out.println() ,  System.err.println etc output to a known
location on the users harddisk namely

%WINDIR%\java\javalog.txt

Those who have been following HTTP-EQUIV's discovery will realise that
this is extremely dangerous, as it will allow execution of arbitrary
code
However since this feature is disabled by default it can be considered
to be very low risk

--
  jelmer



Current thread: