...
This rule applies to server-side applications as well as to clients. Attackers can glean sensitive information not only from vulnerable web servers but also from victims who use vulnerable web browsers. In 2004, Sch����������������‚�š�š�š�š�š�š��������������‚�š�š�š�š�š�z�¶nefeld Sch�����������������€š�š�š�š�š�š�š���������������€š�š�š�š�š�š�z�¶nefeld discovered an exploit for the Opera v7.54 web browser in which an attacker could use the sun.security.krb5.Credentials
class in an applet as an oracle to "retrieve the name of the currently logged in user and parse his home directory from the information which is provided by the thrown java.security.AccessControlException
" [Sch�ƒ¶nefeld 2004].
...