[NOISE] Re: Easter Eggs
At 10:21 AM 9/26/95 -0400, you wrote:
I also think that in Netscape their existance is an indication that the managment at Netscape is a bit less uptight than management at some other places.
Depends on the department. They have at least one manager at Netscape with a permenent case of high blood preasure. (He happens to be in charge of the support department.)
I didn't know about the FishCam Easter Egg, but I know that Netscape has a couple of Easter Eggs related to the activity indicator in the top right of the display. Typically this is the Big N logo with animated meteors, etc. flying by when the window is active. One Easter Egg temporarily turns this into a compass which spins to indicate activity. Another causes the animation to show a dragon (Mozilla) breathing fire for the remainder of the session. I won't spoil your fun by telling how to find them.
If he is not running X Windows, he is going to be searching along time for the Compass easter egg. You also need X windows to find the Mozilla animated icon hack on Jammie Zawinski's page. Which easter eggs that are available is dependant on which client you are running. obNetscapeHack: There is a feature called a "cookie file" in Netscape that is ripe for exploitation as a security leak. If you are using a Netscape server (and you may not even need that), you can feed all sorts of information into it without the user's knowlege. I have heard of one page that overloads the cookie file until the machine runs out of drive space. I am sure that there are other exploitable holes there... Any takers? | Minister of Forced Caffinization in the DNRC | alano@teleport.com | |"The moral PGP Diffie taught Zimmerman unites all| Disclaimer: | | mankind free in one-key-steganography-privacy!" | Ignore the man | | -- PGP 2.6.2 key available on request -- | behind the keyboard.| | http://www.teleport.com/~alano | <fnord> |
Date: Tue, 26 Sep 1995 12:59:54 -0700 From: Alan Olsen <alano@teleport.com> You also need X windows to find the Mozilla animated icon hack on Jammie Zawinski's page. ^^^^^^ Just for the record, that's Jamie. obNetscapeHack: There is a feature called a "cookie file" in Netscape that is ripe for exploitation as a security leak. If you are using a Netscape server (and you may not even need that), you can feed all sorts of information into it without the user's knowlege. I have heard of one page that overloads the cookie file until the machine runs out of drive space. I am sure that there are other exploitable holes there... Any takers? Yikes! That sounds really bad. Do you have any more information on this? For example, can the server write to anything other than $HOME/.netscape-cookies? If I write protect that file, but it's still owned by me, will Netscape still modify it? -- Rick Busdiecker Please do not send electronic junk mail! net: rfb@lehman.com or rfb@cmu.edu PGP Public Key: 0xDBD9994D www: http://www.cs.cmu.edu/afs/cs.cmu.edu/user/rfb/http/home.html send mail, subject "send index" for mailbot info, "send pgp key" gets my key A `hacker' is one who writes code. Breaking into systems is `cracking'.
Actually there is a limit of 20 cokies per web server. I will have to check to see if there is a limit on the size of the cookie. And no you dont need a Netscape server. Its just another HTTP header. What about this: downloading a encoded picture contating graphic description of sex with minors. Would the FBI go around checking peoples cookie files and busting them? Aleph One / aleph1@dfw.net http://underground.org/ KeyID 1024/948FD6B5 Fingerprint EE C9 E8 AA CB AF 09 61 8C 39 EA 47 A8 6A B8 01 On Tue, 26 Sep 1995, Alan Olsen wrote:
obNetscapeHack: There is a feature called a "cookie file" in Netscape that is ripe for exploitation as a security leak. If you are using a Netscape server (and you may not even need that), you can feed all sorts of information into it without the user's knowlege. I have heard of one page that overloads the cookie file until the machine runs out of drive space. I am sure that there are other exploitable holes there... Any takers?
participants (3)
-
Alan Olsen -
Aleph One -
Rick Busdiecker