Re: [Full-Disclosure] automati%20clabs

From: jamie fisher (contact_jamie_fisher_at_yahoo.co.uk)
Date: 08/08/04

  • Next message: Aaron Gray: "Re: [Full-Disclosure] Re: Anyone know IBM's security address? + Google Hack"
    To: full-disclosure@lists.netsys.com
    Date: Sun, 8 Aug 2004 18:04:44 +0100 (BST)
    
    

    Well, something fecked up there in the post...
     
    Try again:
    <script>document.location="http://www.attrition.org/mirror/attrition/2001/07/28/www.attrition.org/hbun.jpg"</script>
    <marquee><script>alert('***')</script>***</marquee>
    <script>alert('***')</script><img src="***http://www.attrition.org/mirror/attrition/2001/07/28/www.attrition.org/hbun.jpg"><marquee>***</marquee>
     
    Cheers!!

    jamie fisher <contact_jamie_fisher@yahoo.co.uk> wrote:

    This is petty, but given the context kind of amusing...
     
    http://automaticlabs.com/products/enkoderform/ offers an obfuscation method for html pages. They also offer (in the advanced form) a link to attritions mirror of the Fluffi Bunni attritoin defacement.
     
    Simply add the following script:
     
    <script>document.location="http://www.attrition.org/mirror/attrition/2001/07/28/www.attrition.org/hbun.jpg"</script>
     
    you can also do this:
     
    <marquee><script>alert('***')</script>***</marquee>
     
    or this:
     
    <script>alert('***')</script><img src="***http://www.attrition.org/mirror/attrition/2001/07/28/www.attrition.org/hbun.jpg"><marquee>***</marquee>
     
    Sunday and its raining...

    ---------------------------------
    ALL-NEW Yahoo! Messenger - all new features - even more fun!

                    
    ---------------------------------
     ALL-NEW Yahoo! Messenger - all new features - even more fun!

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Aaron Gray: "Re: [Full-Disclosure] Re: Anyone know IBM's security address? + Google Hack"