// Proof of concept exploits by Mark Pilgrim // #1 - Will disclose the contents of c:\boot.ini GM_xmlhttpRequest leakage demo ---------------------------------------------------------------------------------------- // #2 - User Scripts Disclosure Greasemonkey script leakage demo

---------------------------------------------------------------------------------------- // #3 - GM_setValue / GM_getValue Information disclosure Greasemonkey function leakage demo

Install mysecretkey.user.js, then refresh this page.

<-- mysecretkey.user.js contains : GM_setValue('my.secret.key', 'f00bar'); --> et.key', 'f00bar'); -->