HomeArchives → by date → July 2005 → July 20 →

Important Greasemonkey alert - Update -

<< Previous Entry | Next Entry>>

Important alert for all Greasemonkey users:

Running a Greasemonkey script on a site can expose the contents of every file on your local hard drive to that site. Running a Greasemonkey script with "@include *" (which, BTW, is the default if no parameter is specified) can expose the contents of every file on your local hard drive to every site you visit. And, because GM_xmlhttpRequest can use POST as well as GET, an attacker can quietly send this information anywhere in the world."

Required actions: uninstall the Greasemonkey extension completely and wait for a patched version which will be due in several days, or update to Greasemonkey 0.3.5 immediately. This version has all functions relevant to the bug blocked.

Also, if you are playing with Joe Gregorio's encrypted data over insecure networks thingy, keep in mind of course to not put private keys in userscripts.


UPDATE: Simon Willison says the bug "illustrates a number of interesting concepts in both web application security and JavaScript", so he helps us Understanding the Greasemonkey vulnerability >


RELATED NEWS
Firefox 1.0.6 and Thunderbird 1.0.6 are out - download now.

IN THE ARCHIVES
2005-04-29 Improving and extending websites with Greasemonkey
2005-06-17 MT-Redland: An RDF Storage Backend for Movable Type

Comments

Comments are closed at the moment. I will post a blog entry as soon as they are available again.

-->

Tools

Recent Comments

Guido Albers on Common Questions (I) at 2006-09-18 19:40
Guido Albers on Common Questions (I) at 2006-09-18 19:39
Sean Roach on World Champion at 2006-09-18 18:52
Frank Kanzler on RSS Feed Reader / News Aggregators Directory at 2006-09-18 15:11
Walter Rafelsberger on Mapping and Visualization Resources at 2006-09-18 03:54
Pieter on Hunters, after all, aren't cooks at 2006-09-14 19:26
Haiko Hebig on Pentax K10D announced (Updated) at 2006-09-13 22:25
Pieter on Pentax K10D announced (Updated) at 2006-09-13 20:04
Donald L Pevsner on Concorde Retirement Update at 2006-09-06 21:01
John Best on RSS Feed Reader / News Aggregators Directory at 2006-08-19 17:49
Titov Denis on RSS Feed Reader / News Aggregators Directory at 2006-08-17 11:20
Haiko Hebig on WASP - Wild Child at 2006-08-07 10:14
Guido Albers on WASP - Wild Child at 2006-08-06 09:43
Frank Wenger on RSS Feed Reader / News Aggregators Directory at 2006-08-04 14:22
Hemaworstje on Spare Part at 2006-08-01 03:55
T.Reader on RSS Feed Reader / News Aggregators Directory at 2006-07-29 09:27
ניו יורק on General Blumenthal Coal at 2006-07-28 22:50
Moritz on "Zwar haben einige Genossen die Dinge zu einseitig gesehen, aber ..." at 2006-07-14 12:12
Pieterjan Lansbergen on Nothing better than a Hill Climb in the Morning at 2006-07-13 20:33
at on Es muss schließlich alles seine Ordnung haben at 2006-07-12 11:33