Home → Archives → by date → July 2005 → July 20 →
Important alert for all Greasemonkey users:
Running a Greasemonkey script on a site can expose the contents of every file on your local hard drive to that site. Running a Greasemonkey script with "@include *" (which, BTW, is the default if no parameter is specified) can expose the contents of every file on your local hard drive to every site you visit. And, because GM_xmlhttpRequest can use POST as well as GET, an attacker can quietly send this information anywhere in the world."
Required actions: uninstall the Greasemonkey extension completely and wait for a patched version which will be due in several days, or update to Greasemonkey 0.3.5 immediately. This version has all functions relevant to the bug blocked.
Also, if you are playing with Joe Gregorio's encrypted data over insecure networks thingy, keep in mind of course to not put private keys in userscripts.
UPDATE: Simon Willison says the bug "illustrates a number of interesting concepts in both web application security and JavaScript", so he helps us Understanding the Greasemonkey vulnerability >
RELATED NEWS
Firefox 1.0.6 and Thunderbird 1.0.6 are out - download now.
IN THE ARCHIVES
2005-04-29 Improving and extending websites with Greasemonkey
2005-06-17 MT-Redland: An RDF Storage Backend for Movable Type
Comments are closed at the moment. I will post a blog entry as soon as they are available again.
-->Guido Albers on Common Questions (I)
at 2006-09-18 19:40
Guido Albers on Common Questions (I)
at 2006-09-18 19:39
Sean Roach on World Champion
at 2006-09-18 18:52
Frank Kanzler on RSS Feed Reader / News Aggregators Directory
at 2006-09-18 15:11
Walter Rafelsberger on Mapping and Visualization Resources
at 2006-09-18 03:54
Pieter on Hunters, after all, aren't cooks
at 2006-09-14 19:26
Haiko Hebig on Pentax K10D announced (Updated)
at 2006-09-13 22:25
Pieter on Pentax K10D announced (Updated)
at 2006-09-13 20:04
Donald L Pevsner on Concorde Retirement Update
at 2006-09-06 21:01
John Best on RSS Feed Reader / News Aggregators Directory
at 2006-08-19 17:49
Titov Denis on RSS Feed Reader / News Aggregators Directory
at 2006-08-17 11:20
Haiko Hebig on WASP - Wild Child
at 2006-08-07 10:14
Guido Albers on WASP - Wild Child
at 2006-08-06 09:43
Frank Wenger on RSS Feed Reader / News Aggregators Directory
at 2006-08-04 14:22
Hemaworstje on Spare Part
at 2006-08-01 03:55
T.Reader on RSS Feed Reader / News Aggregators Directory
at 2006-07-29 09:27
ניו יורק on General Blumenthal Coal
at 2006-07-28 22:50
Moritz on "Zwar haben einige Genossen die Dinge zu einseitig gesehen, aber ..."
at 2006-07-14 12:12
Pieterjan Lansbergen on Nothing better than a Hill Climb in the Morning
at 2006-07-13 20:33
at on Es muss schließlich alles seine Ordnung haben
at 2006-07-12 11:33