Full Disclosure mailing list archives

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype


From: "James Matthews" <nytrokiss () gmail com>
Date: Sun, 7 Oct 2007 01:03:09 -0700

there have always been these vluns

On 10/6/07, Geo. <geoincidents () nls net> wrote:

----- Original Message -----
From: "Thierry Zoller" <Thierry () Zoller lu>

The user clicks on a mailto link, is that untrusted code?

Depends on where the link comes from. If it's a shortcut on the users
desktop no it's not untrusted, if it's in a PDF file you received in your
email then yes it's untrusted.

Anyways, the mailto link
POST IE7 has a flaw/threat/vulnerablity it hasn't had PRE IE7.

The problem here is the root cause, the root cause is that IE7

Ok I'm game, so then show me this exploit without having Acrobat on your
system. IE7 handles mailto links in untrusted web pages. Put the mailto
link
in an untrusted html page and make it work with IE7.

Geo.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/




-- 
http://www.goldwatches.com/mens/cufflinks.html
http://www.jewelerslounge.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: