Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

Re: Windows .ANI LoadAniIcon Stack Overflow
From: Alexander Sotirov <asotirov () determina com>
Date: Tue, 03 Apr 2007 19:53:42 -0700

Larry Seltzer wrote:
Larry, why are you so curious about how this exploit works? 

Because the Firefox docs say they don't support ANI files for cursors
and I can't get any non-malicious ones to work in it. I have to admit
I'm having trouble getting them to work in IE now too.

That's correct, Firefox doesn't support ANI files for cursors. If the
exploitation method was so obvious, we would already have Firefox exploits in
the wild, wouldn't we?

What's wrong with this code?

<HTML>
<BODY>
<style type="text/css">
BODY{cursor: url(http://www.larryseltzer.com/DRUM.ANI);}
</style>

Maybe the url should be in quites? This works for me:
<body style="CURSOR: url('foo.ani')">

Alex

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]