helper app auto-triggered

VERIFIED DUPLICATE of bug 43583

Status

()

Core
Networking
P3
normal
VERIFIED DUPLICATE of bug 43583
18 years ago
18 years ago

People

(Reporter: Gagan, Assigned: Scott MacGregor)

Tracking

Trunk
x86
Windows NT
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

(URL)

(Reporter)

Description

18 years ago
From wdormann@mailandnews.com--

I noticed a problem at this URL:
http://oarnet.tucows.com/adnload/dlzoc.html

 After a second or two, a Save dialog comes up before the file downloads.
Press Cancel.       Now, on the page there is a link that says Click Here if
your download does not start automatically.

If I do this, rather than prompting it to save to my hard drive, it executes
"directly" from the web site.   (downloads and executes with no user
intervention).          What if this was some sort of virus or other malware
executable?
(Reporter)

Comment 1

18 years ago
this is a bad security hazard. marking nsbeta2
Keywords: nsbeta2
(Assignee)

Comment 2

18 years ago
This is because we haven't implemented the dialog yet. This is a feature
exception bug that bill Law is working on.

Once his bug is implemented you'll be prompted with a dialog asking if you want
to open or save this to disk.

That will make this bug invalid. I guess I'll mark it a dup of the UI bug.
(Assignee)

Comment 3

18 years ago
*** Bug 44539 has been marked as a duplicate of this bug. ***
(Assignee)

Comment 4

18 years ago
This is really just a dup of the feature exception bug: 43583 which bill Law is
working on. Implement the helper app dialog asking the user what they want to do
with this content.

*** This bug has been marked as a duplicate of 43583 ***
Status: NEW → RESOLVED
Last Resolved: 18 years ago
Resolution: --- → DUPLICATE

Comment 5

18 years ago
Verified duplicate.
Status: RESOLVED → VERIFIED
You need to log in before you can comment on or make changes to this bug.