Re: [Full-disclosure] Phun! Search



I have exploit code for this issue, which the list won't be getting hold of..
The disclosure was to show that I can ask the slurp robot to cache an
account on the public index, so I can retrieve account information. I ask
the code to cache a copy of 'x user', when 'x' is at critical information
page to obtain access to the yahoo users account. Of course with such a good
0-day, I use it seldom and only on specific targets like yahoo users with
'paid' services and or Yahoo employees.

On 3/22/06, Stan Bubrouski <stan.bubrouski@xxxxxxxxx> wrote:
How old are you? Seriously. I don't know whether you realize just
how completely stupid you come off as to even people new in the
security field. You are a joke. Quit filling this list with crap.
BTW did you even check to see if you Yahoo! will let you view OTHER
people's account stuff? Otherwise it seems pretty useless.

-sb
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Relevant Pages

  • Re: [Full-disclosure] Phun! Search
    ... account on the public index, so I can retrieve account information. ... the code to cache a copy of 'x user', when 'x' is at critical information ... page to obtain access to the yahoo users account. ...
    (Full-Disclosure)
  • Re: Account Forms
    ... BCM sometimes has what's known as a "forms cache" problem. ... The bulk of the forms cache issues in Outlook 2003 are fixed in Service Pack ... > to refigure the account form. ... > I go to the account form now, it's part of the form I was attempting to ...
    (microsoft.public.outlook.program_forms)
  • Re: My profile changed - HELP!
    ... login using my domain account and password and clicking Remember my password. ... This seems to have put in in the cache ahead of the service account so when ... My profile is correct. ... Sharepoint thinks I'm someone else. ...
    (microsoft.public.sharepoint.portalserver)
  • Re: Spyware in Content.IES
    ... believe* have to be deleted from within each user account one by one. ... > wanted to create a cache. ... > you use FAT32 the cluster size increases as the size of the disk partition ... > actually consume 32KB of disk space. ...
    (microsoft.public.windowsxp.security_admin)
  • Entourage 08 having connectivity/authentication issues
    ... error message claiming that their password was not accepted... ... The server for account "account.name@xxxxxxxxxx" returned the error ... I found several suggestions that said to clear the cache, ... not work on the second or third machine/account it was tried on. ...
    (microsoft.public.mac.office.entourage)