Vulnerability Development mailing list archives

RE: New thoughts on CSS


From: jon schatz <jon () divisionbyzero com>
Date: 01 Feb 2002 18:54:45 -0800

On Fri, 2002-02-01 at 17:19, Matt Dickinson wrote:
=- Manolo -=| wrote:

http://www.microsoft.com&item%3Dq209354@212.254.206.213/1338825GHU_98.as

I saw this recently in a newsgroup, I can't believe it's real, and found
no mention when browsing the news sections on either of the company
websites. Isn't this a good example?

this isn't cross site scripting related at all; look at the "@" sign in
the url.  for a quick tutorial on ways to obscure a url, browse slashdot
at -1 and see how many times you can open up goatse.cx by clicking on a
seemingly innocent link....

-jon

-- 
jon () divisionbyzero com || www.divisionbyzero.com
gpg key: www.divisionbyzero.com/pubkey.asc
think i have a virus?: www.divisionbyzero.com/pgp.html
"You are in a twisty little maze of Sendmail rules, all confusing." 

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: