Click Here
home features news forums classifieds faqs links search
6131 members 
Amiga Q&A /  Free for All /  Emulation /  Gaming / (Latest Posts)



Lost Password?

Don't have an account yet?
Register now!

Your support is needed and is appreciated as is primarily dependent upon the support of its users.

Main sections
» Home
» Features
» News
» Forums
» Classifieds
» Links
» Downloads
» OS4 Zone
» IRC Network
» AmigaWorld Radio
» Newsfeed
» Top Members
» Amiga Dealers
» About Us
» FAQs
» Advertise
» Polls
» Terms of Service
» Search

IRC Channel
Ports: 1024,5555, 6665-6669
SSL port: 6697
Channel: #Amigaworld
Channel Policy and Guidelines

Who's Online
22 crawler(s) on-line.
 95 guest(s) on-line.
 2 member(s) on-line.

 pavlor,  fricopal!

You are an anonymous user.
Register Now!
 fricopal!:  7 secs ago
 pavlor:  4 mins ago
 cdimauro:  9 mins ago
 pixie:  11 mins ago
 dalek:  19 mins ago
 alcor:  49 mins ago
 densho:  50 mins ago
 coder76:  1 hr 4 mins ago
 Excalibur:  2 hrs 59 mins ago
 duck:  3 hrs 23 mins ago

/  Forum Index
   /  General Technology (No Console Threads)
      /  So websites can read my clipboard?
Register To Post

Goto page ( 1 | 2 | 3 Next Page )
So websites can read my clipboard?
Posted on 19-Nov-2005 13:49:31
#1 ]
Elite Member
Joined: 22-Aug-2003
Posts: 5900
From: Work

If this is old news then just ignore me.

I just found a "nice" piece of javascript that actually reads out the contents of my clipboard when I'm using IE...

Try it out for yourself:

It's safe, I'm not storing anything. But if you don't trust me, make sure not to have anything secret/sensitive in the copy/paste buffer. And you should of course not trust me. Using Opera, I get nothing. Using IE6 I get the last clipboard entry. I'm really not happy about this.

The php script which reads the form data from the javascript thingie prints out the HTML/javascript used for the excercise...

Luckily I use Opera most of the time, or I would feel a bit awkward right now. Not that I usually have much sensitive data in my clipboard, but you never know when you might have come across a website with a hidden clipboard extractor like this (it doesn't have to auto-submit, it could of course be a part of a login procedure or something, with SQL insert statements instead of prints in the PHP...).

This weeks pet peeve:
Using "voltage" instead of "potential", which leads to inventing new words like "amperage" instead of "current" (I, measured in A) or possible "charge" (amperehours, Ah or Coulomb, C). Sometimes I don't even know what people mean.

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 14:45:14
#2 ]
Super Member
Joined: 8-Apr-2003
Posts: 1907
From: Saltdean, East Sussex, UK


Doesn't seem to work with IBrowse, which is a good thing! I'll give AWeb a go in a mo...

After a decade away from the scene, I am back!

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 15:57:33
#3 ]
Elite Member
Joined: 22-Aug-2003
Posts: 5900
From: Work


Would be a bit strange if Amiga browsers were THAT compatible with IE

This weeks pet peeve:
Using "voltage" instead of "potential", which leads to inventing new words like "amperage" instead of "current" (I, measured in A) or possible "charge" (amperehours, Ah or Coulomb, C). Sometimes I don't even know what people mean.

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 16:11:43
#4 ]
Team Member
Joined: 31-Jul-2003
Posts: 11694
From: Kristianstad, Sweden


Does not work with Firefox, but IE shows it all right .

Site admins are people too..pooff!

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 16:16:48
#5 ]
Regular Member
Joined: 19-Jul-2003
Posts: 333
From: Norwich, UK


Effing piece of sh**!

I'm sick and tired of hearing Microsoft apologists saying how Windows is so big and complex that's why there are the occasional security holes. Rubbish. This is clearly a "feature" deliberately added with absolutely no appreciation for basic security considerations.

Thankfully, it doesn't seem to work in Firefox, which is what any sane person should be using by now (or other alt browsers).

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 16:27:37
#6 ]
Super Member
Joined: 25-Oct-2005
Posts: 1121
From: Michigan, USA

Hi @olegil

->"Try it out for yourself:

It's safe, I'm not storing anything. But if you don't trust me, make sure not
to have anything secret/sensitive in the copy/paste buffer....

I just checked with AWeb 3.5.7 and "Sorry, I don't have anything..."


 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 16:31:31
#7 ]
Regular Member
Joined: 7-Mar-2003
Posts: 464
From: Bucks UK

Yup, it's non-standard, IE only. I was hoping it had been removed by now, but guess I hoped too much.

I'm ashamed to say I actually *shudder* had to write a script that used this when I was at my first job. I can't for the life of me remember why, but I do remember kicking up a fuss about it and then deciding it was less hassle to put it in than argue with management about "trivial" things like browser compatibility, privacy etc. I have sworn never to cross into the dark side ever again.

Snowboarder, Airsofter, Programmer, Writer and AmigaOne XE G4 owner.
Experienced applications developer and part-time snowboard instructor

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 16:32:13
#8 ]
Team Member
Joined: 27-Jun-2003
Posts: 3725
From: The Netherlands


This is clearly a "feature" deliberately added with absolutely no appreciation for basic security considerations.

It might be.. But then again, IE can tell almost everything else about your system to the web developer so that it can read the clipboard out, well I'm not really suprised.

BTW, works on IE7 beta as well so no change there.

Hm.. This seems like a standard java or PHP function, so why doesn't it work in Firefox ? Can I get the PHP source ? (note I'm no PHP programmer... I'm just curious)

Everything you say will be misquoted and used against you..

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 16:33:58
#9 ]
Team Member
Joined: 27-Jun-2003
Posts: 3725
From: The Netherlands


Yup, it's non-standard, IE only.

It's not ? Ok, thanks.

Everything you say will be misquoted and used against you..

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 16:58:19
#10 ]
New Member
Joined: 15-Mar-2005
Posts: 9
From: Unknown

Doesn't get anything from Safari either.

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 17:05:28
#11 ]
Super Member
Joined: 27-Oct-2003
Posts: 1340
From: Unknown


Love it! Love it, in a that-is-so-f**king-stupid-whatever-next sort of way.

I use Safari most of the time.

Mine said,

, &srcRect, m_pScreen, &dstRect


 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 17:07:40
#12 ]
Elite Member
Joined: 22-Aug-2003
Posts: 5900
From: Work


The PHP source is trivial. Just extract the value of the variable "content" as generated by the html form...

This weeks pet peeve:
Using "voltage" instead of "potential", which leads to inventing new words like "amperage" instead of "current" (I, measured in A) or possible "charge" (amperehours, Ah or Coulomb, C). Sometimes I don't even know what people mean.

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 17:12:35
#13 ]
Elite Member
Joined: 22-Aug-2003
Posts: 5900
From: Work


Hehe, obviously you have nothing to be ashamed of if you're writing GUI code

The reason I investigated this code is because it also managed to circumvent the "Block all popups" function in Opera. So I wanted to see how. I turned off everything and reloaded the page. Then I viewed the source. First thing that hit me was "hey, didn't that say _clipboard_? WTF?".

This weeks pet peeve:
Using "voltage" instead of "potential", which leads to inventing new words like "amperage" instead of "current" (I, measured in A) or possible "charge" (amperehours, Ah or Coulomb, C). Sometimes I don't even know what people mean.

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 17:54:58
#14 ]
Cult Member
Joined: 6-Mar-2004
Posts: 578
From: Saarbrücken, Germany

Recently I was asked at my job if I could read an environment variable by a JavaScript. I said this is certainly not possible, because it would be a security risk and I was proved right by a bit of Googleing.
But this is even worse! Many people are copying passwords to the clipboard for not having to type them!
How stupid can the people at Microsoft be? Ok, they allowed scripts to be started by simply opening an email, which is even more stupid...
This company should be prohibited!


Weighty message. You should to read.

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 18:36:41
#15 ]
Super Member
Joined: 6-Feb-2004
Posts: 1382
From: UK


I'm sick and tired of hearing Microsoft apologists saying how Windows is so big and complex that's why there are the occasional security holes. Rubbish. This is clearly a "feature" deliberately added with absolutely no appreciation for basic security considerations.

Features like this are logical enough when you consider what IE's sole purpose was for most of its life - a weapon to kill Netscape. The developer's main focus was simply to add as many features as possible in double-quick time, regardless of any side-effects, so that IE could do things Netscape Navigator couldn't, making it look like a better browser.

History records that this tactic worked brilliantly...

But now MS has to fix the pox-mess that is IE's code base in order to make it secure, while also out-featuring Mozilla/Firefox. I think they'd be better off scrapping it and building a new browser from scratch.

Who do you serve, and who do you trust? - Galen

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 19:48:46
#16 ]
Elite Member
Joined: 29-Nov-2004
Posts: 8554

That's sweet

Thanks Olegil. I've been wanting to spend a few days figuring out just how much info can be gotten from browsers as 'playing around.' Nice to know MS has out best interests in mind there as always

FireFox, epiphany, and konqueror all come up with nada here, not surprisingly.

Are we not done with the same silly arguments and flames yet??!

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 20:05:03
#17 ]
Super Member
Joined: 25-Mar-2003
Posts: 1786
From: Denmark


a good way to "steal" code from Microsoft... make a website with special interreset for Microsoft developers... and hope that they have a copy of most of their code in their clipboard And then it would even be their own fault

Best regards,
hnl_dk - Henning Nielsen Lund [Denmark]

Please send no PM to me, email me if you want to contact me. See you somewhere else.

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 21:07:02
#18 ]
Elite Member
Joined: 29-Nov-2004
Posts: 8554

Meh- M$ code not worth anything

Are we not done with the same silly arguments and flames yet??!

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 21:09:10
#19 ]
Team Member
Joined: 27-Jun-2003
Posts: 3725
From: The Netherlands


Meh- M$ code not worth anything

Not even learning material ?

How not to do it...

Last edited by Seer on 19-Nov-2005 at 09:09 PM.

Everything you say will be misquoted and used against you..

 Status: Offline
Profile     Report this post  
Re: So websites can read my clipboard?
Posted on 19-Nov-2005 21:10:20
#20 ]
Elite Member
Joined: 29-Nov-2004
Posts: 8554

Hmm, this WOULD be a fun thing to publicize and then post to slashdot, now that I think of it

Are we not done with the same silly arguments and flames yet??!

 Status: Offline
Profile     Report this post  
Goto page ( 1 | 2 | 3 Next Page )

[ home ][ about us ][ privacy ] [ forums ][ classifieds ] [ links ][ news archive ] [ link to us ][ user account ]
Copyright (C) 2000 - 2019 was originally founded by David Doyle