Re: www.security7.ch.vu

From: Duane Beck (dbeck@legendent.com)
Date: 03/02/02


From: "Duane Beck" <dbeck@legendent.com>
To: <lordsoth8@bigfoot.com>, <security-basics@securityfocus.com>
Date: Fri, 1 Mar 2002 19:10:28 -0500


> http://www.security7.ch.vu/
>
> When entering, it claims that you are exposed and tracked and a lot of
information
> is stored on your computer (doh..altho i dont keep names on it etc..).
> What caught my attention is that the show you the contents of your
root directory
> (c:\ for a windows machine...).
> What's alarming is that I don't see how this thing could've been done.
I dont allow
> any shares, I dont allow any services, and unless it is an IE exploit
of some sort,
> there is no other way to explain it. My firewall (TPF) handles all the
microsoft
> network issues and only internal LAN can even see my nbt name etc...
> this is weird.
> Anybody know how this is done ?

http://www.sexbunnys.at/evidence/7/m.html (one of the frames) contains
the following tag.

<iframe src="file:///C|/" height=200 width=640 marginwidth=0
marginheight=0 scrolling=no frameborder=3 vspace=2>

It's showing you a directory of your local C: drive, which is valid on
the client side. As far as I can tell, it doesn't actually expose any
local files to anyone remotely. It just looks like a trick to get you
to sign up for a service.



Relevant Pages

  • Re: OT:Scrotex Question 2
    ... You dont know my job, just as you dont know anything ... Poor simple tools Aid has no proof to back up his claims ... Why would you deny being Steven Jones the registrant of the ... this mission to try and expose me. ...
    (uk.sport.football.clubs.liverpool)
  • Re: OT:Scrotex Question 2
    ... You dont know my job, just as you dont know anything about me:) Yet i know you dont have a job and claim benefits, dont own a house, dont own a car or have a full licence, dont take holidays and much much more. ... Poor simple tools Aid has no proof to back up his claims about me and is now looking to verify himself with mentalwool. ... Why would you deny being Steven Jones the registrant of the domain www.scoopex.co.uk and then post online as 'Ste Jones'? ... I have no points to score simple tools Aid, you are the one on this mission to try and expose me. ...
    (uk.sport.football.clubs.liverpool)
  • Re: OT:Scrotex Question 2
    ... You dont know my job, just as you dont know anything about me:) Yet i know you dont have a job and claim benefits, dont own a house, dont own a car or have a full licence, dont take holidays and much much more. ... Poor simple tools Aid has no proof to back up his claims about me and is now looking to verify himself with mentalwool. ... Why would you deny being Steven Jones the registrant of the domain www.scoopex.co.uk and then post online as 'Ste Jones'? ... I have no points to score simple tools Aid, you are the one on this mission to try and expose me. ...
    (uk.sport.football.clubs.liverpool)
  • Re: OT:Scrotex Question 2
    ... You dont know my job, just as you dont know anything ... Poor simple tools Aid has no proof to back up his claims ... Why would you deny being Steven Jones the registrant of ... this mission to try and expose me. ...
    (uk.sport.football.clubs.liverpool)
  • Re: OT:Scrotex Question 2
    ... You dont know my job, just as you dont know anything ... Poor simple tools Aid has no proof to back up his claims ... domain www.scoopex.co.uk and then post online as 'Ste Jones' ... mission to try and expose me. ...
    (uk.sport.football.clubs.liverpool)