Results 1 to 5 of 5

Thread: Please make it so we can attach .html and .html files

  1. #1

    Thread Starter
    Fanatic Member Wynd's Avatar
    Join Date
    Dec 2000
    Location
    In a bar frequented by colossal death robots
    Posts
    772

    Please make it so we can attach .html and .html files

    Alcohol & calculus don't mix.
    Never drink & derive.

  2. #2
    Hyperactive Member thinktank2's Avatar
    Join Date
    Nov 2001
    Location
    Arctic
    Posts
    272
    You are asking to open a security hole, right ???

  3. #3
    PowerPoster rjlohan's Avatar
    Join Date
    Sep 2001
    Location
    Sydney, Australia
    Posts
    3,205

    Re: Please make it so we can attach .html and .html files

    Originally posted by Wynd
    Re: Please make it so we can attach .html and .html files
    Both, or just one?



    Anyway, just c&p the HTML to a text file, and away you go.
    -----------------------------------------
    -RJ
    [email protected]
    -----------------------------------------

  4. #4

    Thread Starter
    Fanatic Member Wynd's Avatar
    Join Date
    Dec 2000
    Location
    In a bar frequented by colossal death robots
    Posts
    772
    Rjlohan, that should be .htm and .html files. TT, I don't want to open a security hole, I just don't think I should have to rename .htm* files to .asp just to be able to attach them. How would having that create a security hole anyway?
    Alcohol & calculus don't mix.
    Never drink & derive.

  5. #5
    Hyperactive Member thinktank2's Avatar
    Join Date
    Nov 2001
    Location
    Arctic
    Posts
    272
    Originally posted by Wynd
    How would having that create a security hole anyway?
    Suppose a person with a malicious intent attaches a html file(loaded with javascript stuff) and you click to open it.

    the url of the file would be something like....

    http://www.vbforums.com/attachment.php?s=&postid=######

    the browser will see this as a page belonging to the domain
    www.vbforums.com. The script can then read your vbforums cookies, password information and secretly make a request (such as downloading an image) to the perpetrator's site pushing the stolen info with the querystring . The perpetrator can then create a cookie with this info in his computer and can impersonate you.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  



Click Here to Expand Forum to Full Width