Full Disclosure mailing list archives

Re: new worm - "warm-pussy.jpg".


From: Valdis.Kletnieks () vt edu
Date: Wed, 12 Nov 2003 23:52:28 -0500

On Thu, 13 Nov 2003 01:08:06 PST, Gadi Evron <ge () egotistical reprehensible net>  said:

HTML _is_ plain-text.
Just because the server sends it as plain text doesn't mean the browser 
won't execute it.

It does.

Well.. sure... a .JPG might have some executable code in it, right? :)

At least this time they're improving.  They're executing plain text that
was called .jpg.  Last time, they executed javascript that was in the
comments field of an actual jpg.

Attachment: _bin
Description:


Current thread: