Bugtraq mailing list archives

Re: IE can read local files


From: smoyzis () AMERITECH NET (Steve Moyzis)
Date: Sat, 5 Sep 1998 17:14:34 -0400


For a really scary Demonstration of how this works, go to:

http://onion-router.nrl.navy.mil/Tests.html

This is a Department of Defense Web Site with a Server especially designed for
this purpose.  It was able to read my e-mail address, my ISP, my local IP#,
The city my ISP is located in, my Browser version and it was able to read
my Autoexec.bat, among other files.  Follow all the links for a really good
Demo
(I don't know what the Model Railroad one is for, probably more Hack tests)

Steve Moyzis  -- smoyzis () ameritech net



Current thread: