RE: www.security7.ch.vu

From: Mark Kovacic (Mark.Kovacic@barrsystems.com)
Date: 03/01/02


Date: Fri, 1 Mar 2002 12:41:01 -0500
From: "Mark Kovacic" <Mark.Kovacic@barrsystems.com>
To: <lordsoth8@bigfoot.com>, <security-basics@securityfocus.com>

I took a look at what they are doing.

Sneaky, a server side script to access your hard drive from the web
browser (i.e. locally)

They are just setting a client side scripting item to look at your local
drive from your machine.

Mark Kovacic, Systems Programmer
Barr Systems, Inc. www.barrsystems.com
352-491-3100 Mark.Kovacic@barrsystems.com

-----Original Message-----
From: LS [mailto:hydrax@netvision.net.il]
Sent: Wednesday, February 27, 2002 6:46 PM
To: security-basics@securityfocus.com
Subject: www.security7.ch.vu

Hi all,

I was sent the following address:

http://www.security7.ch.vu/

When entering, it claims that you are exposed and tracked and a lot of
information
is stored on your computer (doh..altho i dont keep names on it etc..).
What caught my attention is that the show you the contents of your root
directory
(c:\ for a windows machine...).
What's alarming is that I don't see how this thing could've been done. I
dont allow
any shares, I dont allow any services, and unless it is an IE exploit of
some sort,
there is no other way to explain it. My firewall (TPF) handles all the
microsoft
network issues and only internal LAN can even see my nbt name etc...
this is weird.
Anybody know how this is done ?

Regards,
Eli



Relevant Pages

  • Re: Choosing whitch button will act as submit button
    ... Use the script exactly as supplied for the browser. ... server-code cannot decide whitch button should be the submit button. ... one server side form tag, ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: different behavior - localserver vs prod server
    ... But I don't understand what you mean when you say to type the src urls ... into the browser to see if they are correct. ... > Smart Navigation and Client Range checking are implemented by client script, ... and how it behaves on the server. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Using anchor links within pages defined by GETS
    ... So the content in the browser ... sure the submitted value for pid is valid and not a NULL or SQL ... What URL is sent to the server? ... because your script should never see the ...
    (comp.lang.php)
  • Re: Is script type="text/perl" OK?
    ... :} I've asked this on a html forum but I'll ask it here also. ... Well, as long as your browser is able to execute the script, sure. ... Since the server is doing the running of the ...
    (comp.lang.perl.misc)
  • Re: connection drops while script running
    ... The browser send a header to the server, ... kill the connection without notice". ... be carefull with session expiring during script execution. ...
    (comp.lang.php)