About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2004-12-18, 09:38
Doc 057 Doc 057 is offline
Regular
 
Default good ol IE

found something 4 yuz-

17.12.2004 17:33:10

Dan Ilett

ZDNet UK

December 17, 2004, 13:10 GMT



Even SP2 versions of Microsoft's Internet Explorer are vulnerable to a spoofing exploit published yesterday

A vulnerability researcher posted details of a dangerous Internet Explorer (IE) flaw on Thursday that allows phishers to spoof Web sites more realistically than ever before.



According to security company Secunia, Paul from Greyhats -- a research group -- has published details of a vulnerability that can be exploited to spoof the content of any Web site.

Using the exploit, scammers are able to manipulate all versions of IE, including Windows XP SP2 -- the latest and most secure version of the browser -- and spoof the URL and SSL signature padlock located at the bottom of the browser screen.

The vulnerability is caused by a cross-site scripting vulnerability in the DHTML Edit ActiveX control, but because the flaw is within the browser, it can be used against any Web site, Secunia said.

"That is huge," said Thomas Kristensen, chief technology officer for Secunia. "When you cross-site script a Web site, the user can’t see that anything unusual is happening. The URL looks like it's a legitimate site and if you go to the SSL padlock, it will show a certificate for the site even though it is controlled by malicious scripting."

"The malicious Web site can control what is seen in the address bar. People still don't realise the significant impact of cross-site scripting. This is the vulnerability that phishers and scammers have been looking for. You could also steal cookies from any Web site," Kristensen warned.

"The most likely outcome is a phishing email, where users click on a link, then open the browser. They then briefly see the URL of the malicious Web site, and then see the scam Web site," Kristensen added.

Nick McGrath, Microsoft's security spokesman, and the Microsoft UK security team was unavailable to comment at the time of writing because they are in the United States. The company has previously frowned upon researchers who have posted exploits without letting it know first.

Kristensen said he was unsure why Paul chose to publish the exploit before informing Microsoft. Secunia has developed an exploit test on its Web site which is available for download.

Secunia has labelled the vulnerability as "moderately critical" because people cannot use it to access systems.

--- 057
 #2 
Old 2004-12-18, 20:57
Bastard Of The Barrel Bastard Of The Barrel is offline
Regular
 
Default Re: good ol IE

You're a fucking idiot if that suprises you, and it wouldn't suprise me if it did.

B B
 #3 
Old 2004-12-18, 22:23
Zonko Zonko is offline
Regular
 
Default Re: good ol IE

http://secunia.com/multiple_browsers_window_injection_vulnerability_t est/

It's not just IE.
 #4 
Old 2004-12-19, 00:54
Doc 057 Doc 057 is offline
Regular
 
Default Re: good ol IE

B0B-- you're such a pussy- you're just a bitch with a keyboard who gets fucked with @ school so u talk mad shit on the net-- does it make you feel better?-- well, i'd be pretty frustrated too if i knew i had no chance in hell of ever getting laid- cya round bitch- 057
 #5 
Old 2004-12-19, 08:56
marleyandmarley marleyandmarley is offline
Regular
 
Default Re: good ol IE

so does anyone know how you can go about doing this?
 #6 
Old 2004-12-19, 10:16
jamez jamez is offline
Regular
 
Default Re: good ol IE

go on bugtraq, look for the reporting of it, look at proof of concept
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics