Wednesday, August 23, 2006

Thinking Outside The Box (More JavaScript Security Risks)

Periodically someone gets creative with JavaScript and manages to do something that its creators did not anticipate. The latest one that I found uses inline CSS styles and JavaScript to determine which sites on a pre-defined list you have visited. You can certainly see the potential for some nefarious uses. Here's a link to the original article and a version that works on IE.


