Full Disclosure mailing list archives
Re: Sensitive Information Disclosure Vulnerability in Kinetics Kiosk Product
From: Sam Evans <wintrmte () gmail com>
Date: Thu, 18 Aug 2005 10:29:00 -0600
Jason, Not that I disagree with you here, but I am not sure I understand why you think that connecting to a host outside the private address ranges is irresponsible by the company? The connectivity from this Kiosk to the destination displayed could be one of: The destination host only allows point to point connectivity, controlled by a firewall or that the connectivity from this Kiosk is through a VPN connection. I also don't see the difference of using Internet Explorer versus any other browser. Script errors are script errors and will be displayed regardless which browser they use unless specifically disabled (as you mentioned). On 8/18/05, Jason Coombs <jasonc () science org> wrote:
The following script error message was noted being displayed this morning on an airline check-in kiosk manufactured by Kinetics USA. Vendor: Kinetics USA www.kineticsUSA.com <http://www.kineticsUSA.com> Line: 107 Char: 2 Error: object expected Code: 0 URL: http://151.151.10.46:64080/attract ?time=1124376480&TransactionID=HNL_KIOSK09-050818044716 Clearly, building a product such as a publicly-accessible airline passenger check-in kiosk using Internet Explorer and Windows is a very bad design decision if you care at all about preventing this sort of information disclosure. Even so, IE can and should be configured so as not to display such script errors. Furthermore, the use of an IP address that is outside of the RFC 1918 private subnet address range appears very irresponsible. Sincerely, Jason Coombs jasonc () science org _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Sensitive Information Disclosure Vulnerability in Kinetics Kiosk Product Jason Coombs (Aug 18)
- Re: Sensitive Information Disclosure Vulnerability in Kinetics Kiosk Product Sam Evans (Aug 18)
- Re: Sensitive Information Disclosure Vulnerability in Kinetics Kiosk Product Peter Besenbruch (Aug 18)
- Re: Sensitive Information Disclosure Vulnerability in Kinetics Kiosk Product Jay D. Dyson (Aug 19)