Re: Session Variables - why aren't novice developers warned?

Tech-Archive recommends: Fix windows errors by optimizing your registry



"BillE" <belgie@xxxxxxxxxxx> wrote in message
news:uiKMIWs8GHA.4012@xxxxxxxxxxxxxxxxxxxxxxx

Possibly, Mark, but I think that even thorough testers might overlook the
possibility of clicking File-New-Window in Internet Explorer if they
weren't previously aware that it could cause problems. After all, they
are testing the application, not the behavior of Internet Explorer!

Then they need to be testing the application under the various different
functional scenarios of the platform it's running under...
Opening a new window is just one of these. Same as the effect of turning
JavaScript off, etc...

Which returns to the main point - how is a developer / tester to become
aware of this pitfall?

Trial and error. Every new runtime scenario encountered by the development /
testing team gets added to the knowledge pool...


.



Relevant Pages

  • Re: Session Variables - why arent novice developers warned?
    ... My assertion, however, is that the documentation should identify ... this potential problem in the first place. ... possibility of clicking File-New-Window in Internet Explorer if they ... not the behavior of Internet Explorer! ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Session Variables - why arent novice developers warned?
    ... possibility of clicking File-New-Window in Internet Explorer if they weren't ... not the behavior of Internet Explorer! ... You see it as a pitfall - others may see it as a boon. ... client which will open in a new window. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Internet Explorer JavaScript insecure function
    ... Product: Microsoft Internet Explorer ... I discovered a javascript function called ... With "file.writeline" function the attacker can ... This code writes a file called "proof.txt" in the hard disk, ...
    (Vuln-Dev)
  • [Full-Disclosure] Internet Explorer JavaScript insecure function
    ... Product: Microsoft Internet Explorer ... I discovered a javascript function called "file.writeline" may be ... An attacker may use this function writting JavaScript code in posts of forums, guestbooks, etc for owning ... this may be potentially dangerous for Internet Explorer users. ...
    (Full-Disclosure)
  • RE: Internet Explorer JavaScript insecure function
    ... Product: Microsoft Internet Explorer ... I discovered a javascript function called ... With "file.writeline" function the attacker can ... this may be potentially dangerous for Internet Explorer users. ...
    (Vuln-Dev)