Vulnerability Development mailing list archives

Re: Web Browsers vulnerable to the Extended HTML Form Attack (IE and OPERA)


From: Random Chaos <randomchaos () geocities com>
Date: Thu, 14 Feb 2002 09:06:49 -0600


Likewise for Netscape 6.2.1 for linux.


Opera 6.0 Technology Preview 2 & 3 for linux do not have any such dialog and
attempt to connect to whatever port is specified.

Random Chaos


Patrick Kuiper wrote:

> Netscape® Communicator 4.78 is giving the same error
>
>
>>>Exploit Example.
>>>available at http://eyeonsecurity.net/advisories/showMyCookie.html
>>>
>>FYI: Mozilla 0.9.8+ gives an alert:
>>"Access to the port number given has been disabled for security reasons."
>>
>
> Cu Patrick
>
>




Current thread: