Bugtraq mailing list archives
Re: AIM forced behavior "issue"
From: Knud Erik Højgaard <kain () egotrip dk>
Date: Mon, 16 Jul 2001 22:44:53 +0200
Example <META
HTTP-EQUIV="refresh"CONTENT=0;URL=aim:addbuddy?listofscreennames=mindfliporg ,mfliporb,mflipmax,mflips0nic,mflipzorcon&groupname=mindfliporg>
A web page loaded with the above code in it's META REFRESH tag would automatically add a group to the users buddylist called mindfliporg and add buddy's mindfliporg, mfliporb, mflipmax, mflips0nic, mflipzorcon to the group.
We tried some similar stuff with icq a while ago, live example at http://knudergud.dk/dev/icq.html .. it seems broken now, but the idea should be obvious. adding to a contact list using javascript, requiring no user interaction.. stupid software. -Knud
Current thread:
- AIM forced behavior "issue" orb (Jul 15)
- Re: AIM forced behavior "issue" Knud Erik Højgaard (Jul 16)
- Re: AIM forced behavior "issue" Re:ICQ and MSIE allow execution of arbitrary code Bojidar Alexandrov (Jul 18)
- Re: AIM forced behavior "issue" Knud Erik Højgaard (Jul 16)
