TUCoPS :: Browsers :: expl4843.htm

Internet Explorer remote discolure vulnerability
5th Nov 2001 [SBWID-4843]

	iexplorer remote discolure vulnerability


	all versions ?


	dzzie posted :

	a  remote  server  can  poll  a  surfers  computer  and  determin   some
	applications they have installed by trying a  load  an  image  with  the
	file:// protocol.

	if the file is found on disk the javascript onload event  fires..if  not
	the onerror event fires..



	you  can  also  check  out  the  remote  system  by  setting  an  iframe
	src=file:// to common paths to txt or xml files..if they are found  they
	will raise the onload event (oddly enough  .html  extension  wont  raise




