Re: [Full-Disclosure] RE: FWD: Internet Explorer URL parsing vulnerability

From: S . f . Stover (attica_at_stackheap.org)
Date: 12/09/03

  • Next message: S G Masood: "[Full-Disclosure] FWD: Internet Explorer URL parsing vulnerability"
    To: S G Masood <sgmasood@yahoo.com>
    Date: Tue, 9 Dec 2003 09:16:25 -0500
    
    
    

    On 09 Dec 03 10:22:59AM S G Masood[sgmasood@yahoo.com] wrote:
    : ># POC ##########
    : >http://www.zapthedingbat.com/security/ex01/vun1.htm
    :

    Interestingly enough, MSIE for OS X doesn't display this behavior. My address
    bar contained this URL:

    http://www.microsoft.com%01@zapthedingbat.com/security/ex01/vun2.htm

    -- 
    aka Dolph Longhorn
    GPG Key ID: 0xF8F859D0
    http://pgp.mit.edu:11371/pks/lookup?search=0xF8F859D0&op=index
    "There is no such thing as right and wrong, there's just popular opinion."
    -Jeffrey Goines
    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: S G Masood: "[Full-Disclosure] FWD: Internet Explorer URL parsing vulnerability"

    Relevant Pages

    • Win XP and MSIE 6 steal my graphics files
      ... When I view websites with MSIE 6 running on XP Pro, ... refuse to display some graphics files. ... I've found similar problems with other web sites I've ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • IE 6 connects by DSL or DUN, but always shows "cannot connect to server"
      ... actually display the webpage. ... connect to server" is displayed, no matter where or when I ... I have re-installed MSIE 6 several times, ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Help Me Please #2 "Display all images with full quality"
      ... I am stumped as to how to get my MSIE to load up website ... > All my display settings are correct, but to get a clear image I need ... > quality" every time a web page loads, is there any way to get my MSIE ... > images with full quality" every time I view a web page. ...
      (microsoft.public.windowsxp.general)
    • Re: apache (mod_deflate?) weirdness
      ... > display hello.md5 and hello.txt properly. ... > aren't ALL of these files text/plain? ... What do you mean by "web browsers"? ... known MSIE "feature" where it thinks it knows better than the server ...
      (comp.os.linux.networking)
    • Re: texlive problems
      ... okular can display .dvi files. ...
      (Fedora)