Search This Blog

Sunday, August 31, 2008

Be Very Careful with this......

Don't know hw many of you are aware of this????
We do copy various data by ctrl+c for pasting elsewhere. This copied data is stored in clipboard and is accessible from the net by a combination of Javascripts and ASP.
Just try this:
1) Copy any text by ctrl+c
2) Click the Link: http://www.friendlycanadian.com/appl.../clipboard.htm
3) You will see the text you copied on the Screen which was accessed by this web page. Do not keep sensitive data (like passwords, creditcard numbers, PIN etc.) in the clipboard while surfing the web. It is extremely easy to extract the text stored in the clipboard to steal your sensitive information.

This is not a kind of bug. It's an option provided by IE. If you want you can disable. You can configure IE to restrict this behavior.
The following settings are required-
Internet Explorer 5 and 6
1. Open IE, click menu Tools->Internet Options.
2. Click the Security tab.
3. Under that, Select a Web content zone to 'Internet' zone, where you want to prevent Web sites from accessing your clipboard.
4. Click Custom Level.
5. In the Scripting section, look for “Allow paste operations via script�, click Prompt or Disable.
6. Click OK.

No comments: