Announcement

Collapse
No announcement yet.

Yet another IE vulnerability

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • NewKids123
    replied
    I knew that patch would affect me porno surfing wise and buggy.

    Thank god I use firebird.

    Hm
    Hm

    Leave a comment:


  • highwizard
    Guest replied
    Originally posted by skroo
    As for the AV detection, AV is used for a lot of things it shouldn't be. That's a whole other can of worms, though.
    Can of Worms... Good pun.

    Leave a comment:


  • skroo
    replied
    Originally posted by stingerbee
    the only problem is up to date virus definitions throw up a message indicating a spoofed url. also, latest windows updates prevent this from working
    Well... Yes. That's the point of patching your system.

    As for the AV detection, AV is used for a lot of things it shouldn't be. That's a whole other can of worms, though.

    Leave a comment:


  • stingerbee
    replied
    the only problem is up to date virus definitions throw up a message indicating a spoofed url. also, latest windows updates prevent this from working

    Leave a comment:


  • Sparks-Kelly
    replied
    Originally posted by GidGreen
    If you pop open mozilla or netscape and visit that webpage, then click the little button that sends you to supposedly microsoft, it will essentailly take you to
    http://www.microsoft.com%01@zapthedi.../ex01/vun2.htm
    instead.

    the possibilities for exploitation are endless.
    Ok Thank you. That helps alot. I have been using the Internet for a long time but I just didn't get it that well.

    Leave a comment:


  • GidGreen
    replied
    Originally posted by Sparks-Kelly
    I dont understand how you do it. The whole http://User@Domain Is that a www address? Or what does that mean?
    If you pop open mozilla or netscape and visit that webpage, then click the little button that sends you to supposedly microsoft, it will essentailly take you to
    http://www.microsoft.com%01@zapthedi.../ex01/vun2.htm
    instead.

    the possibilities for exploitation are endless.

    Leave a comment:


  • lil_freak
    replied
    Originally posted by Sparks-Kelly
    I dont understand how you do it. The whole http://User@Domain Is that a www address? Or what does that mean?
    How long have you been using a computer? Or the internet?

    Leave a comment:


  • bascule
    replied
    Originally posted by Sparks-Kelly
    I dont understand how you do it. The whole http://User@Domain Is that a www address? Or what does that mean?
    IE has a UTF-16 address bar, and consequently it's valid for certain bytes to have a value of zero. However, clearly some of the display code is using zero terminated strings. Consequently, any part of the URL which lies after the zero is truncated.

    Leave a comment:


  • Sparks-Kelly
    replied
    I dont Get it.

    I dont understand how you do it. The whole http://User@Domain Is that a www address? Or what does that mean?

    Leave a comment:


  • EcstacyX
    replied
    This small exploit becomes handy in the Fruad division. he he he.

    Leave a comment:


  • bascule
    started a topic Yet another IE vulnerability

    Yet another IE vulnerability

    But this one's kind of fun... it corrupts the contents of the address bar with a null character, which allows its contents be spoofed:

    http://zapthedingbat.com/security/ex01/vun1.htm
Working...
X