Re: Konqueror: URL address bar spoofing vulnerabilities



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Robert Swiecki wrote:
The second one is based on the http URI scheme which allows embedding
user/password parameters into it, i.e. http://user:password@xxxxxxxxxxx
Such parameters can contain whitespaces, so the attack vector is quite
obvious.

http://alt.swiecki.net/konq3.html

Tested with Konqueror 3.5.7 on Linux 2.6

This does interesting things to firefox as well. Specifically, it hangs
seemingly indefinably (with no cpu utilization). Tested with firefox-2.0.0.6 on
Foresight Linux (firefox=/foresight.rpath.org@fl:1-devel//1/2.0.0.6-1-1).

smithj

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.4 (GNU/Linux)

iD8DBQFGt6KR0e1Yawpq2XMRAptmAJ9YTUDtNKUctdrfPDLGn6sWug/ivwCeIYvE
IpsCSHCIHi6dyzWPebwp/wU=
=bLFr
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: [Full-disclosure] Konqueror: URL address bar spoofing vulnerabilities
    ... Such parameters can contain whitespaces, so the attack vector is quite ... Tested with Konqueror 3.5.7 on Linux 2.6 ...
    (Full-Disclosure)
  • Re: User Linux
    ... there's issues no matter ehat distro you use. ... > konqueror is almost unusable because of font problems, ... I use XFce4 and konqueror works fine and looks great for me. ... churn then you might look at the RHEL clones like White Box Linux, ...
    (Fedora)
  • Re: Forward slashes in filenames
    ... Konqueror knows that / is one of 2 invalid characters ... r>> The filename record in the filesystem contains '%2f' not '/'. ... r>> possible to create a file with / or ASCII NUL in its name on a Linux ... translation, but this is some 'feature' of its file-name entry dialog -- ...
    (comp.os.linux.misc)
  • Re: [SLE] Make available off-line by Konqueror
    ... >> Hi folks, ... It's a command line tool rather ... > than a Konqueror one, but it's very useful and can certainly do what you want ... UNIX since 1989, linux since 1994, SuSE since 1998 ...
    (SuSE)
  • Re: cdrom problem
    ... mount the device at boot time. ... Konqueror seems to do this for some reason; ... If that doesn't help, "lsof +D /mnt/cdrom" ... Brainbench MVP for Linux Admin / mail: ...
    (comp.os.linux.misc)