oh man, ohman ohman ohman.
I can't believe what I just tried, worked.
I setup a new user account on my machine, "test", logged in, started Opera - it setup a wonderful fresh profile for me in /home/test/.opera. This included a cookies4.dat file, which would store any cookies for me.
In Firefox, cookies are stored in a cookies.txt file. This file has very strict permissions - nobody can view it except the owner. This is for a very good reason - if anyone else can read it, they can copy it and they'll know all your cookies.
And, well, if you're me, that means they'll be able to log into my microsuck forums account and well, make this post. I'm logged in as test now, I coppied the cookies4.dat file from /home/declan/.opera/cookies4.dat into /home/test/.opera and when I came to microsuck.com/forums I was already logged in - didn't need to enter a password!
Badbad Opera.
Are the permissions fucked up like this on Windows too?
EDIT: konq users are safe - I can't access /home/declan/.kde
atall - smart people those KDE devs.
EDIT:
A security vulnerability is a flaw in a product that makes it infeasible