In other words, running a Greasemonkey script on a site can expose the contents of every file on your local hard drive to that site. Running a Greasemonkey script with "@include *" (which, BTW, is the default if no parameter is specified) can expose the contents of every file on your local hard drive to every site you visit. And, because GM_xmlhttpRequest can use POST as well as GET, an attacker can quietly send this information anywhere in the world.(This hole has since been patched — but it's just an example of the types of vulnerability that GreaseMonkey may open up. I love GreaseMonkey, but — as with anything else — be careful.)
« Older Arimaa... | Esquivalience-n. the willful a... Newer »
This thread has been archived and is closed to new comments
posted by weapons-grade pandemonium at 2:17 PM on August 22, 2005