Full Disclosure mailing list archives

Re: The email that hacks you


From: Guifre <guifre.ruiz () gmail com>
Date: Wed, 28 Nov 2012 12:00:09 +0100

Hello,

"I can also confirm that this attack works on iPhone, iPad and Mac's
default mail client."

Of course, it works anywhere where arbitrary client-side code can be
executed... IMAHO, the issue here is not your iphone loading images,
there are millions of attack vectors to trigger this attack... The
problem is the CSRF weaknesses of your router admin panel that should
be fixed by synchronizing a secret token or by using any other well
known mitigation strategy against these attacks.

Best Regards,
Guifre.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: