Re: Microsoft ISA Server HTTP error handler XSS (TL#007)
http-equiv_at_excite.com
Date: 07/17/03
- Previous message: Last Stage of Delirium: "[LSD] Critical security vulnerability in Microsoft Operating Systems"
- Maybe in reply to: Thor Larholm: "Microsoft ISA Server HTTP error handler XSS (TL#007)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 17 Jul 2003 02:27:13 -0000 To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
<!--
http:// -->
This is very interesting. A side 'benefit' is that we can mask our
For an href in html in order to mask the true destination the <a
This can be defeated quite simply like so:
<A href="http://%09%09%09%09%09%09%09
In an html mail message [default in Outlook Express] plus restricted
End Call
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
With a growth rate exceeding 110%, the TICSA security practitioner
http://www.trusecure.com/offer/s0100/
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
=""%09onerror="document.scripts[0].src=%27http%5Cx3a%
5Cx2f%
5Cx2f
true url with the same scheme.
href="....>bloatedcorp.com</a>, can be manipulated by trivial
javascript to generate a custom representation in the status bar to
fool our recipient should they 'hover' the mouse over the link.
09www.malware.com">http://www.microsoft.com>
zone in Outlook Express 6 [again default] where no scripting is
allowed, the above link when presented to the recipient in an html
email message, and tested by 'hovering' the mouse over it, yields
nothing. Blank. Thereafter accepting the url, transports us to our
site as required.
Are You "Certifiable"? Summer's Hottest Certification Just Got HOTTER!
certification is one of the hottest IT credentials available. And now, for
a limited time, you can save 33% off of the TICSA certification exam! To
learn more about the TICSA certification, and to register as a TICSA
candidate online, just go to
Relevant Pages
... This is just a simple exploit utilizing the Object Data vulnerability ... coupled with the GreyMagic no-script HTML ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
(NT-Bugtraq)
... The way that Microsoft patched the new RPC Part II vulnerability ... Summer's Hottest Certification Just Got HOTTER! ... To learn more about the TICSA certification, ...
(NT-Bugtraq)
... accurately parse the lists of vulnerable machines produced by the scan ... of addresses directly on the script. ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification ...
(NT-Bugtraq)
... The default Enhanced Security Configuration of IE ... access to files and folders on the local machine from the internet. ... With a growth rate exceeding 110%, the TICSA security practitioner certification is one of the hottest IT credentials available. ... And now, for a limited time, you can save 33% off of the TICSA certification exam! ...
(NT-Bugtraq)
... the patch for each systems affected. ... in the right frame. ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
(NT-Bugtraq)