User: Password:
|
|
Subscribe / Log in / New account

Confused deputy

Confused deputy

Posted Jul 28, 2005 4:45 UTC (Thu) by jwb (guest, #15467)
In reply to: Confused deputy by bignose
Parent article: Greasemonkey gets into trouble

No, it really isn't. The problem here is that greasemonkey works by injecting strings into an untrusted markup stream, when it should have been programmatically fiddling the model using priviledged APIs. Mozilla already has the the security model you recommend, but greasemonkey poked a big hole in it.


(Log in to post comments)


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds