Re: V8.3 Apache and Javascript in HTML files? (was Re: VMS 7.3 vs 8.x - java in HTML files, Hmm.)



Hoff Hoffman wrote:

patrick jankowiak wrote:

After FTP-ing some hundreds of HTML files over, I noticed that once they got on the system live, I could use any web browser and view source, and one short line of javascript had been inserted in each HTML file near the beginning. I verified this by FTP-ing the files back to myself and looking at them, sure enough it was there.

....

Was VMS 8.3 set up wrong with some default I don't know about or should it be playing with my HTML files? Did Apache do this? Has anyone else seen this?


OpenVMS itself doesn't have this HTML Javascript insertion option, barring manually running a perl script, DCL procedure or other such against the HTML files.

Some more details, please? What was the Javascript? Which Apache?

Does the Javascript appear if you TYPE the files on OpenVMS? And was the line in the source for the file; in the original copy?

Was any HTML editor used? (In my experience, Adobe Macromedia Dreamweaver doesn't insert HTML into the file without explicit request, but I've used other HTML packages which gratuitously reformat and otherwise insert changes into the HTML file.)

I've certainly seen various Microsoft Windows packages insert Javascript into the data on the fly, usually as part of a Windows security package. One of the Norton packages was using this.

It's not typical that Apache inserts anything into its HTML, but I expect its possible. (Apache could probably make you your coffee, if you connected your hardware and loaded the right options into the .htbeverage file; remember to enable the RSS feed into the brewer.)

Indeed, I don't have the answers, and didn't document it at the time. I'm trying to see if Mr. Smiley remembers.

It is comforting to know VMS did not do it, but I doubted it would do so without informing me. I did look at the files on the serial connected terminal and the line was there.

I can say that the pages were all done manually with windows notepad, which does not behave that way. I never use special HTML editors because of cargo cult issues.

Thank you,
Patrick
.



Relevant Pages

  • Re: V8.3 Apache and Javascript in HTML files? (was Re: VMS 7.3 vs 8.x - java in HTML files, Hmm.
    ... got on the system live, I could use any web browser and view source, and one short line of javascript had been inserted in each HTML file near the beginning. ... Did Apache do this? ... OpenVMS itself doesn't have this HTML Javascript insertion option, barring manually running a perl script, DCL procedure or other such against the HTML files. ... I've certainly seen various Microsoft Windows packages insert Javascript into the data on the fly, usually as part of a Windows security package. ...
    (comp.os.vms)
  • Security holes in Hotmail, Yahoo, and other webmails
    ... Most webmails services and applications have huge security holes on the ... execution of malicious javascript and HTML code ... some parts of the user's mailbox, without use of javascript. ... Cross-site scripting vulnerabilities on the yahoo.com domain was reported ...
    (Vuln-Dev)
  • Re: HTML4.01 STRICT and hyperlinks with target
    ... new window *in HTML* instead of in JavaScript. ... have a link open a new window in HTML instead of in JavaScript. ... I know this is not a great reason, but I think it is reason ...
    (comp.infosystems.www.authoring.html)
  • [Full-disclosure] [RT-SA-2009-001] IceWarp WebMail Server: Cross Site Scripting in E
    ... RedTeam Pentesting discovered that the IceWarp ... WebMail Server is prone to Cross Site Scripting attacks in its email view. ... To prevent the execution of JavaScript and VBScript code in HTML emails ... and to remove unwanted HTML tags, the IceWarp WebMail Server filters HTML ...
    (Full-Disclosure)
  • [RT-SA-2009-001] IceWarp WebMail Server: Cross Site Scripting in Email View
    ... RedTeam Pentesting discovered that the IceWarp ... WebMail Server is prone to Cross Site Scripting attacks in its email view. ... To prevent the execution of JavaScript and VBScript code in HTML emails ... and to remove unwanted HTML tags, the IceWarp WebMail Server filters HTML ...
    (Bugtraq)