h54481 s 00001/00001/00028 d D 1.4 96/06/27 09:28:28 mrm 5 4 c putback the fix this time e s 00000/00000/00029 d D 1.3 96/06/25 12:08:45 mrm 4 3 c fixed broken link e s 00001/00001/00028 d D 1.2 95/12/12 11:57:02 mrm 3 1 c layout fix e s 00000/00000/00000 d R 1.2 95/12/11 22:02:34 Codemgr 2 1 c SunPro Code Manager data about conflicts, renames, etc... c Name history : 2 1 sfaq/example/replacePropertiesFile.html c Name history : 1 0 people/mrm/sfaq/example/replacePropertiesFile.html e s 00029/00000/00000 d D 1.1 95/12/11 22:02:33 mrm 1 0 c date and time created 95/12/11 22:02:33 by mrm e u U f e 0 t T I 1 Java Security FAQ: Changing Properties

Java Security FAQ: Changing Properties


Here's an applet that tries to change a property, by writing to the file ~/.hotjava/properties:

D 3 E 3 I 3 E 3

and here's the source.

Conclusion:

Never add ~/.hotjava or ~/.hotjava/properties to your acl.write property! If you do, applets will be able to alter your appletviewer properties in surprising ways. The properties file is one file that you want to be especially sure cannot be tampered by outside applets.


D 5 Back to the Java Security FAQ E 5 I 5 Back to the Java Security FAQ E 5 E 1