Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Netscape Exploit SOLVED
From: robin.hood () IBM NET (Edwin Li-Kai Liu)
Date: Fri, 20 Jun 1997 04:38:18 +0700


Yusuf Motiwala wrote:

Hello Paul,

I think this will not work. First, on reload, netscape fills
< INPUT TYPE=FILE ..> only if the file is local e.g. it will
work with file:/myserver/rootpath/abc.html but will not work with
http://myserver/abc.html.

First of all, I tried the "form field shift" effect on Netscape 4.0 and
it actually works. My investigation is under this condition: local file
html, reload instead of pressing enter on Location bar. I have created a
html document that contains a form on the local machine, I loaded it
into my browser. Then, I changed the form fields and reload the page
again. The data is in a correct order, but does not fit in the right
form field. I mean, the form data 'shifted' to another field.

The next problem would be, how can we make the client side reload this
page automatically? There would be several ways to accomplish. It will
work with JavaScript, but it 'might' also work if the document expiry
date is specified.

Second, history.go(0) will not reload the file unless it is on local
machine (or not in cache..????).

True, but I didn't remember if he mentioned that before.

--

Robin Hood
------------------------------------
Dreaming of a butterfly, fly into the sky.
¹Ú·QÅܦ¨½¹½º¡A­¸¤W¤ÑªÅ¡C



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]