Domain: hollywood.com
Stories and comments across the archive that link to hollywood.com.
Stories · 4
-
"A Sound of Thunder" Movie This Summer
Syberghost writes "Ray Bradbury's classic short story "A Sound of Thunder" is being released thus summer as a movie. It's directed by Peter Hyams, who's done the time travel thing before, but it appears that some of the major characters from the Bradbury story aren't in the credits." -
Equilibrium
The_Hiro writes ""Farenheit 451 - meets - Brave New World - meets - Matrix" (minus the overdone wire work). Created on a limited budget, Equilibrium combines the best of sci-fi with the action genre. Unfortunately, the marketing droids at Dimension have neglected to promote the film (release date: Dec. 6th). Chud.com has a glowing review of the film and some pretty pictures. Check out the trailer also." -
MSIE's Cookies Are Public
If you're using Microsoft Internet Explorer running on Microsoft Windows, turn off Javascript now. Your cookie file is readable by any hostile website. Or, if you'd like to see the security hole in action, leave Javascript on and check it out: "Open Cookie Jar." (read more)Peacefire webmaster Bennett Haselton is on a roll. After discovering yesterday's Hotmail hole, today he's published his discovery that MSIE's Javascript contains a bug that allows any hostile website to obtain your cookies.
Essentially the bug is that MSIE's Javascript is not very smart about determining which domain you're coming from. If the URL you're looking at has its "/" characters replaced by the hex representation "%2f", it can be fooled into thinking your path is actually a very long machine name. Because it interprets that path wrongly, a well-placed ".yahoo.com" in the URL can make Javascript think it should be using Yahoo's cookies - and Javascript can be told to deliver those cookies back to the hostile server.
Bennett and I believe the bug is confined to the Javascript code in MSIE, but we have not done extensive testing to determine this. For now, at least, we believe turning off Javascript will be sufficient to eliminate this security hole.
Or, you could migrate to another browser or operating system...
We have only tested this with IE 5, and Windows 95/98. Reports of success or failure with other versions would be welcome.
After Bennett explained to me how this works, I wrote a short CGI script to demonstrate what lurks in cookie files. Instead of silently stealing your private information and squirreling it away for later use, it echoes that information back to you (and then forgets it, of course). Updated: That script has been rewritten by and is now hosted at securityspace.com. For best results, first go log into amazon.com, type your zip code into hollywood.com, and visit playboy.com. Then go visit securityspace's general info page and click the "click here."
Newsbytes and CNET have picked up this story and have good writeups.
-
Lucasfilm Explains Lack Of TPM DVD
DanteKy writes "Hollywood.com has another article on the release of the VHS release of The Phantom Menace. Also, Lynne Hale, a spokeswoman for Lucasfilm 'explains' why there is no DVD just yet. The article also mentions that in some Asian locations, TPM will be released on VCD. I know it isn't DVD, but at least it is a start." I'm still waiting for Episodes IV, V and VI on DVD, as well. I'm beginning to wonder if we're going to have to wait until they're all finished before we see them at all.