RE: [Full-Disclosure] 3 new MS patches next week...

From: Can Erkin Acar (canacar_at_eee.metu.edu.tr)
Date: 01/12/04

  • Next message: Dr. Peter Bieringer: "RE: [Full-Disclosure] Re: bzip2 bombs still causes problems in antivirus-software"
    To: Exibar <exibar@thelair.com>
    Date: Mon, 12 Jan 2004 10:07:01 +0200
    
    

    On Sun, Jan 11, 2004 at 12:17:23PM -0500, Exibar wrote:
    >
    > >
    > > This really long 'form action' item
    > > http://www.citibank.com:achaaa9uwdtyazjwvwaaaa9p398haaa9uwdtyazjwv
    > > waboundpyw
    > > wgc2l6zt00pjxtvgc2l6zt00pjxywwgc2l6zt00pjxt398haaa9uwdtyazjwvwaaou
    > > ndpywwgc2l
    > > 6zt00pjxtvgc2l6zt00pjxvgc2l6zt00pjxt@211.239.150.170/login/form.php
    > >
    > The above http: line doesn't make use of the 0x01 exploit. In order to make
    > use of that exploit, you NEED "0x01" in there just before the @ symbol.

    Yes, however this is the link from the 'fake' page. The distributed pishing
    e-mail (which I also received) does contain 0x01 character at the proper
    place, on the 'Click here to login' link directing users to this login page.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Dr. Peter Bieringer: "RE: [Full-Disclosure] Re: bzip2 bombs still causes problems in antivirus-software"

    Relevant Pages

    • Elementary security questions
      ... easy to ensure that the login process was handled entirely over SSL, ... converting a request for the login page made via http into a request ... In my JSP ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: SSL Forms Authentication Redirect - Problem Redirecting out of HTTPS
      ... allowing an authentication cookie to be passed over an HTTP ... My login script goes into SSL just fine. ... The load balancer is maintaining server affinity. ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: How to implement a automatic login function
      ... a web client which programmatically send http post request to send login ... I am simply trying to simulate a normal login. ... username and password via a post and authenticate using the ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: SSL Forms Authentication Redirect - Problem Redirecting out of HTTPS
      ... allowing an authentication cookie to be passed over an HTTP ... My login script goes into SSL just fine. ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: Basic password security question
      ... Look at the pages - they never post that form over HTTP - usually the login form posts to an HTTPS address.... ... You need SSL - and if you have it for the rest of your site, why not for you login page too? ... Developing More Secure Microsoft ASP.NET 2.0 Applications ...
      (microsoft.public.dotnet.framework.aspnet.security)

    Loading