Vulnerability Development mailing list archives

Re: Web Browsers vulnerable to the Extended HTML Form Attack (IE and OPERA)


From: Chip McClure <vhm3 () hades gigguardian com>
Date: Thu, 7 Feb 2002 11:52:59 -0800 (PST)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The same error was given with Mozilla 0.93 (FreeBSD 4.4)

- -----
Chip McClure
Sr. Unix Administrator
GigGuardian, Inc.

http://www.gigguardian.com/
- -----

On Thu, 7 Feb 2002, Mark Renouf wrote:

obscure wrote:


Exploit Example.

available at http://eyeonsecurity.net/advisories/showMyCookie.html

FYI: Mozilla 0.9.8+ gives an alert:
"Access to the port number given has been disabled for security reasons."




-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.8
Comment: Made with pgp4pine 1.76

iQA/AwUBPGLbIJuKtP8CSC69EQI8aACffUkVzIVdCF8eF1JaVg3BEulwdWkAnRrV
dCX+IWpP8kTl5NFMKz8io+bJ
=aDu3
-----END PGP SIGNATURE-----



Current thread: