|
Save the teapot fund New CSS web design for Wibble proudly provided by Kelv. Please contact the webmaster with any questions or concerns. |
Wibble > List archives > bugtraq > 2000 [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: Hotmail security hole - injecting JavaScript using <IMG
On Wed, 5 Jan 2000 11:37:49 +0100, Henri Torgemane wrote: >> What could be useful would be a tag working like >> <blockscript key=randompieceofdata> >> >> </blockscript key=samepieceofdata> This would just try to fix one of the symptoms. Something more fundamentally is wrong: Data and executable code do not belong together. Violation of this brought us macro viruses, HTML e-mail that steals passwords, trojans, etc. Carsten Kuckuk (only speaking for himself)
|