D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Secure web browsing with live distro

 

On Friday 06 July 2007 09:46, Simon Waters wrote:
> Tom Potts wrote:
> > All the above is valid - however it is also valid for any non simple
> > display type activity in a browser - Java applets, ActiveX even PDF and
> > Flash viewers have the potential to mess with your LAN (or the WAN) as
> > they are compiled they can do it a lot faster - and you don't get to read
> > the code to find out whats happening!
>
> The Java security model (for Applets) specifically prevents this, as
> Java can only originate connections back to the host the applet is
> served from. It doesn't stop Java telling the browser to do silly things.
I thought you could use an applet to modify the dom it was contained in and so 
get out that way? Thats in IE as opposed to liveconnect(?) which does the 
same for Mozilla/FF.
I think both probably need JS enabled tho..
Tom te tom te tom


-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/linux_adm/list-faq.html