Full Disclosure mailing list archives

Re: IE7 Information Disclosure - For sale


From: Travis Good <tgood () mindsecurity net>
Date: Fri, 5 May 2006 15:32:42 -0700 (PDT)


I'll give you 10.99+tip for it if you also throw in a large sausage pizza.

On Thu, 4 May 2006, 0x80 () hush ai wrote:


I just found a second bug that allows one to remotely retrieve the
contents of other tabs inside of IE7.

Again, for sale.  Highest bidder.

Exploit example is to trick luser to visiting website which would
then download contents of all open tabs including cookie and
session information.



Concerned about your privacy? Instantly send FREE secure email, no account required
http://www.hushmail.com/send?l=480

Get the best prices on SSL certificates from Hushmail
https://www.hushssl.com?l=485

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Travis Good, CISSP, IAM, IEM

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: