Security Incidents mailing list archives

Interesting


From: "http-equiv () excite com" <http-equiv () malware com>
Date: Wed, 26 Feb 2003 20:01:34 -0000



Here's an interesting one:

xx.x.xx.xx - - [26/Feb/2003:02:36:41 -0500] "GET /html.exe.zip 
HTTP/1.1" 200 2245 "-" "Mozilla/5.0 (LINUX; means; Linux Is Not UniX; 
<script>alert('XSS@'+document.URL)</script>; +++ath0)"

Hats off to the lad in KL. It worked and I loved it!

"tags in host names"
"tags in search keywords"

seem to have been done.

-- 
http://www.malware.com




----------------------------------------------------------------------------

<Pre>Lose another weekend managing your IDS?
Take back your personal time.
15-day free trial of StillSecure Border Guard.</Pre>
<A href="http://www.securityfocus.com/stillsecure";> http://www.securityfocus.com/stillsecure </A>



Current thread: