|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2004-12-18, 09:38
|
Doc 057 
Regular
|
|
|
|
good ol IE
found something 4 yuz-
17.12.2004 17:33:10
Dan Ilett
ZDNet UK
December 17, 2004, 13:10 GMT
Even SP2 versions of Microsoft's Internet Explorer are vulnerable to a spoofing exploit published yesterday
A vulnerability researcher posted details of a dangerous Internet Explorer (IE) flaw on Thursday that allows phishers to spoof Web sites more realistically than ever before.
According to security company Secunia, Paul from Greyhats -- a research group -- has published details of a vulnerability that can be exploited to spoof the content of any Web site.
Using the exploit, scammers are able to manipulate all versions of IE, including Windows XP SP2 -- the latest and most secure version of the browser -- and spoof the URL and SSL signature padlock located at the bottom of the browser screen.
The vulnerability is caused by a cross-site scripting vulnerability in the DHTML Edit ActiveX control, but because the flaw is within the browser, it can be used against any Web site, Secunia said.
"That is huge," said Thomas Kristensen, chief technology officer for Secunia. "When you cross-site script a Web site, the user cant see that anything unusual is happening. The URL looks like it's a legitimate site and if you go to the SSL padlock, it will show a certificate for the site even though it is controlled by malicious scripting."
"The malicious Web site can control what is seen in the address bar. People still don't realise the significant impact of cross-site scripting. This is the vulnerability that phishers and scammers have been looking for. You could also steal cookies from any Web site," Kristensen warned.
"The most likely outcome is a phishing email, where users click on a link, then open the browser. They then briefly see the URL of the malicious Web site, and then see the scam Web site," Kristensen added.
Nick McGrath, Microsoft's security spokesman, and the Microsoft UK security team was unavailable to comment at the time of writing because they are in the United States. The company has previously frowned upon researchers who have posted exploits without letting it know first.
Kristensen said he was unsure why Paul chose to publish the exploit before informing Microsoft. Secunia has developed an exploit test on its Web site which is available for download.
Secunia has labelled the vulnerability as "moderately critical" because people cannot use it to access systems.
--- 057
|
|
#2
 2004-12-18, 20:57
|
Bastard Of The Barrel 
Regular
|
|
|
|
Re: good ol IE
You're a fucking idiot if that suprises you, and it wouldn't suprise me if it did.
B  B
|
|
#3
 2004-12-18, 22:23
|
Zonko 
Regular
|
|
|
|
Re: good ol IE
http://secunia.com/multiple_browsers_window_injection_vulnerability_t est/
It's not just IE.
|
|
#4
 2004-12-19, 00:54
|
Doc 057 
Regular
|
|
|
|
Re: good ol IE
B0B-- you're such a pussy- you're just a bitch with a keyboard who gets fucked with @ school so u talk mad shit on the net-- does it make you feel better?-- well, i'd be pretty frustrated too if i knew i had no chance in hell of ever getting laid- cya round bitch- 057
|
|
#5
 2004-12-19, 08:56
|
marleyandmarley 
Regular
|
|
|
|
Re: good ol IE
so does anyone know how you can go about doing this?
|
|
#6
 2004-12-19, 10:16
|
jamez 
Regular
|
|
|
|
Re: good ol IE
go on bugtraq, look for the reporting of it, look at proof of concept
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|