Full Disclosure mailing list archives
Re: MSIE7 browser entrapment vulnerability (probably Firefox, too)
From: "Matt S" <m.schalkham () gmail com>
Date: Mon, 26 Feb 2007 12:59:59 -0500
PoC successful on firefox 1.5.0.3 on linux along it didn't load the wormhole site, just left a blank page for any page browsed after your etrap. Wormhole site was seen on IE 7.0.5346.5 on xp
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- MSIE7 browser entrapment vulnerability (probably Firefox, too) Michal Zalewski (Feb 22)
- Re: MSIE7 browser entrapment vulnerability (probably Firefox, too) Michal Zalewski (Feb 23)
- Firefox: onUnload tailgating (MSIE7 entrapment bug variant) Michal Zalewski (Feb 23)
- Re: MSIE7 browser entrapment vulnerability (probably Firefox, too) Jeffrey Katz (Feb 24)
- Re: MSIE7 browser entrapment vulnerability (probably Firefox, too) Michal Zalewski (Feb 26)
- Re: MSIE7 browser entrapment vulnerability (probably Firefox, too) Matt S (Feb 26)