[Full-Disclosure] FWD: Internet Explorer URL parsing vulnerability

From: S G Masood (sgmasood_at_yahoo.com)
Date: 12/09/03

  • Next message: S-Quadra Security Research: "@Mail web interface multiple security vulnerabilities"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 9 Dec 2003 10:03:55 -0800 (PST)
    
    

    Zap The Dingbat http://www.zapthedingbat.com/ posted
    this to Bugtraq:

    Internet Explorer URL parsing vulnerability
    Vendor Notified 09 December, 2003

    # Vulnerability ##########
    There is a flaw in the way that Internet Explorer
    displays URLs in the address bar.

    By opening a specially crafted URL an attacker can
    open a page that appears to be
    from a different domain from the current location.

    # Exploit ##########
    By opening a window using the http://user@domain
    nomenclature an attacker can hide
    the real location of the page by including a 0x01
    character after the "@" character.
    Internet Explorer doesn't display the rest of the URL
    making the page appear to be
    at a different domain.

    # POC ##########
    http://www.zapthedingbat.com/security/ex01/vun1.htm

    # Tested ##########
    Internet Explorer
    Version 6.0.2800.1106C0
    Updates: SP1, Q810847, Q810351, Q822925, Q330994,
    Q828750, Q824145

    # Credit ##########
    Zap The Dingbat
    http://www.zapthedingbat.com/

    __________________________________
    Do you Yahoo!?
    Free Pop-Up Blocker - Get it now
    http://companion.yahoo.com/

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: S-Quadra Security Research: "@Mail web interface multiple security vulnerabilities"

    Relevant Pages

    • Re: File>Open puzzle
      ... Believe it or not the autocomplete is a feature of internet explorer. ... Do both computers have the same version of IE? ... files in that folder starting with that character. ...
      (microsoft.public.windowsxp.perform_maintain)
    • Using IE for FTP
      ... When using Internet Explorer as an FTP client, ... the password contains the '@' character. ... Perhaps an escape sequence? ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Center - "x.html" 370 Bytes yEnc
      ... I have not seen your code, but I am guessing the reason the character is not ... what attributes are removed in xhtml, ... When Using this technique in Internet Explorer in an aspx document the ... Thom Little www.tlanet.net Thom Little Associates, ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: ? euro symbol
      ... No -- the Euro symbol isn't in ASCII, which is a very old character set ... Some fonts however, don't include a Euro symbol, so a square or question ... You could try using a touch of CSS to persuade Internet Explorer to use ...
      (comp.lang.php)
    • Re: Setting default programs in XP Pro - How???
      ... program for surfing the web. ... Zap ... | Custom | Internet Explorer. ...
      (microsoft.public.windowsxp.general)