Full Disclosure mailing list archives
Re: The email that hacks you
From: Guifre <guifre.ruiz () gmail com>
Date: Wed, 28 Nov 2012 12:00:09 +0100
Hello, "I can also confirm that this attack works on iPhone, iPad and Mac's default mail client." Of course, it works anywhere where arbitrary client-side code can be executed... IMAHO, the issue here is not your iphone loading images, there are millions of attack vectors to trigger this attack... The problem is the CSRF weaknesses of your router admin panel that should be fixed by synchronizing a secret token or by using any other well known mitigation strategy against these attacks. Best Regards, Guifre. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- The email that hacks you Bogdan Calin (Nov 28)
- Re: The email that hacks you Guifre (Nov 28)
- Re: The email that hacks you Bogdan Calin (Nov 28)
- Re: The email that hacks you Christian Sciberras (Nov 28)
- Re: The email that hacks you aditya (Nov 28)
- Re: The email that hacks you Bogdan Calin (Nov 28)
- Re: The email that hacks you aditya (Nov 28)
- Re: The email that hacks you Bogdan Calin (Nov 28)
- Re: The email that hacks you Guifre (Nov 28)