Vulnerability Development mailing list archives

Odd MSIE html parsing


From: "Matthew S. Hallacy" <poptix () techmonkeys org>
Date: Wed, 2 Jan 2002 07:36:29 -0600

I recieved an odd spam today, the links were obfuscated as follows:

<A HREF="http://www.ca1.waredet.net.co.fr^T^B^T^E^T|https.travel.bzah.com^B">

clicking on the link in MSIE shows the following in the address bar:
'http://www.ca1.waredet.net.co.fr(?????)|https.travel.bzah.com/'
while it's really going to https.travel.bzah.com (a stupid angelfire spam site,
die die die)

Comments? I'm curious as to why MSIE allows control characters in the url
like this, it didn't work in Mozilla.

                                - Matthew S. Hallacy
-- 


Current thread: