Hacker News new | past | comments | ask | show | jobs | submit login

I'm confused what happens here. Sure, you are tricked into pressing Return in a file open dialog. But you can't open the “file” `C:\`… right? Does that somehow let the page access files on the disk?

The file dialog allows opening of folders as well, so the exploit is basically tricking the user into saying "I want to upload the folder C:\"

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
