advertisement
javaboutique
Search Tips
Articles  |   Tutorials  |   Reviews  |   Tools  |   by Category  |   by Date  |   by Name  |   Submit  |   Source  |   Forums  |  
javaboutique
Browse DevX


Partners & Affiliates











advertisement

JavaBoutique : Articles :

Applet Persists Indefinitely; Breaks into JavaScript

Contents
Introduction
Intro pt 1
Intro pt 2
Intro pt 3
Intro pt 4
An Illustration of these Techniques
An Applet Example
An Active X Example
A Pseudo-Constructor Example
Pseudo-Constructor pt 2
Applet Persists Indefinitely; Breaks into JavaScript
Persistence
Conclusion

Conclusion

In Explorer, the merchant's home site is placed into the new window – this works until the applet gets confused about frame addressing (hey, it’s experimental) - and you can purchase additional items. All of this is done by breaking into the JavaScript interpreter for the current page, from within a persistent applet. Notice that the JAVA frame which was launched within the commercial site persists into any site, and that the buttons continue to work – JAVA can do all the things that JAVA can do, on any page, and no one is able to stop it without my permission. This results from the formation of a pseudo-constructor.

Within the commercial site, the applet can carry information from page to page, without the use of cookies. This results from exploiting a new kind of HTML memory. A program which is launched on one particular page can break into JavaScript on every page within the launching site. This appears to work on all recent browsers, and not just on Netscape.

How does one break into JavaScript? Get the JSObject for the current window, with MAYSCRIPT permission, and then remember it – this window object can then access JavaScript, on Netscape, even when the HTML page has been changed, and when the new page no longer has MAYSCRIPT permission (as long as the <APPLET></APPLET> tags in the original HTML page are surrounded by <FORM> and </FORM> brackets). It is easier to access JavaScript ‘on site’ because the applet’s init() is called whenever the applet is reloaded, and you can use that to refresh the window object so that it remains current – Explorer as well as Netscape can then access JavaScript successfully. For some reason, it is possible on both browsers to jump to a new page, from anywhere, using JavaScript, when that page is in a new window.

I’m sure there are lots of other fun things that one can do – I would think that the designers of JAVA never expected a JAVA class to break away from the launching page and to develop a life of its own.


Post your feedback in the JavaBoutique Forum

You can find the original exploratory article here.


Lane Friesen

lanelise@dowco.com

How to Add Java Applets to Your Site

New on the Java Boutique:

New Review:

Time Management Made Easy with the Quartz Enterprise Job Scheduler
Why not just use the Java timer API? This open source scheduling API boasts simplicity, ease-of-integration, a well-rounded feature set, and it's free!

New Applet:

Reverse Complement
Reverse Complement is a simple applet that converts DNA or RNA sequences into three useful formats.

Elsewhere on internet.com:

WebDeveloper Java
Lots of Java information on webdeveloper.com

WDVL Java
Thorough Java resource at the Web Developer's Virtual Library.

ScriptSearch Java
Hundreds of free Java code files to download.

jGuru: Your View of the Java Universe
Customizable portal with online training, FAQs, regular news updates, and tutorials.

 Microsoft Visual Studio 2010 Showcase
 Avaya Developer Showcase
 MSDN Spotlight
 PHP for Windows Showcase
XML error: undefined entity at line 39
advertisement
Receive Articles via our XML/RSS feed
Receive Articles via our XML/RSS feed

JavaBytes
Internet Cyclone
This powerful, easy-to-use, internet optimizer is for Windows 95, 98, ME, NT, 2000 and XP. It's designed to automatically optimize your Windows settings, boosting your Internet connection up to 200%.

Windows 7: From Beta to Final Code in One Year
Google Shows Off Chrome OS, Releases Source
Microsoft Shows Off Silverlight 4, IE9 Plans
Metasploit Expands Vulnerability Test Framework
HyperCard Reborn?
Fedora 12 Takes Aim at Linux Networking
Top Supercomputer Nearly Doubles in Speed
Fedora 12 Linux Tackles Virtualization
Apple Gives iPhone Developers App Status Tracker
Novell Sets OpenSUSE 11.2 Free

Creating Custom Export Filters for StarOffice with XSLT
WPF Wonders: Using DataTemplates
Crystal Reports Family Offers Options for Developers
Avaya Aura Session Manager video
Avaya Aura Overview video
Exploring HTML 5's Audio/Video Multimedia Support
Overriding Virtual Functions? Use C++0x Attributes to Avoid Bugs.
Understanding the Cloud Computing Security Vulnerabilities
Cisco and IBM Target a Greener World
Upgrade to Visual Studio 2010 with the Ultimate Offer

Advertising Info  |   Member Services  |   Contact Us  |   Help  |   Feedback  |   Site Map  |   Network Map  |   About

internet.commediabistro.comJusttechjobs.comGraphics.com

Search:

WebMediaBrands Corporate Info

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs