exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

ie-spoof.txt

ie-spoof.txt
Posted Mar 28, 2008
Authored by Juan Pablo Lopez Yacubian

It appears that Internet Explorer 7 may have an address bar spoofing vulnerability.

tags | advisory, spoof
SHA-256 | c2f099b1e957ea9fc84dce9b9a2509835c81dfe944c0e3fb7455aa7afb74d1a0

ie-spoof.txt

Change Mirror Download
Hello, as they are? This time I communicate with you to let you know of a vulnerability such as "spoofing" in the Internet Explorer 7.0 (tested at 8.0 and does not work). 
Creating a pop-up malformated can put any address in the address bar in the body any page or content.

This flaw is possible because if in the address bar we eg

Address # direction

The numeral makes the first address is run and what comes after the numeral does not interfere with the original page. This is why creating popup with the special measures and to try to pass such an easterly direction popup displayed the end of the address and did not show the direction it runs. (Special measures are important because if it does not work largest).

Just a single click in the body popup to this reveals the true direction, which can be equal to dodge an event like javascript onblur or onfocus .. Anyway that's more serious an attack that a proof of concept.

Here I leave the proof of concept.

http://es.geocities.com/jplopezy/iespoof.html

Greetings from Argentina!

Juan Pablo Lopez Yacubian
fuzzertina.blogspot.com
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close