Boo

Jul. 20th, 2005 01:35 am
mrlachatte: (Default)
[personal profile] mrlachatte
There goes my great discovery of greasemonkeyed.  This message makes it clear that GreaseMonkey is a huge security risk as of this moment (as does [livejournal.com profile] atrustheotaku's post) and I've disabled GM until further notice, or at least until 0.3.5 becomes compatible with Deer Park.
(deleted comment)

Date: 2005-07-19 09:46 pm (UTC)
From: [identity profile] mrlachatte.livejournal.com
If you don't have the neutered version, a website with appropriately malicious Javascript that matches any Greasemonkey script (even *) can retrieve any file on your hard drive and send it anywhere on the internet.

Date: 2005-07-19 09:51 pm (UTC)
From: [identity profile] wardrich.livejournal.com
wow! That's sort of weird. I thought greasemonkey was only one-way and that the sites wouldn't know you had it on. That's some CRAZY security hole, though. Could the sites that took advantage of this hole be in trouble for invasion of privacy?

December 2007

S M T W T F S
      1
2345678
9101112131415
16171819202122
23242526 272829
3031     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jul. 9th, 2025 04:36 am
Powered by Dreamwidth Studios