EverCrest Message Forums
You are not logged in. Login or Register.
Author
Topic: New URL spoofing exploit on IE
diadem
eet bugz
posted 12-12-2003 06:43:08 PM
http://secunia.com/internet_explorer_address_bar_spoofing_test/

(thanks hot-deals.org for the info)


test of yahoo w/ evercrest url <-- click that link and you will see evercrest on the status bar and the url after you click it, but it will in fact be yahoo. wow, that was damn easy.

[ 12-12-2003: Message edited by: diadem ]

play da best song in da world or me eet your soul
Oh shi...
what
posted 12-12-2003 06:47:57 PM
quote:
diadem had this to say about Knight Rider:
http://secunia.com/internet_explorer_address_bar_spoofing_test/

(thanks hot-deals.org for the info)


test of yahoo w/ evercrest url <-- click that link and you will see evercrest on the status bar and the url after you click it, but it will in fact be yahoo. wow, that was damn easy.


test?

Oh shi...
what
posted 12-12-2003 06:48:26 PM
What is the character key of that 
Oh shi...
what
posted 12-12-2003 06:51:12 PM
nm..found it
&nbsp;
can you please fix my title
posted 12-12-2003 06:53:44 PM
ok so how do you fix that?
Im confused as always[xIMG]http://img.villagephotos.com/p/2003-8/356687/somthorsig3.JPG[/img]
Random Insanity Generator
Condom Ninja El Supremo
posted 12-12-2003 06:55:40 PM
1) No fix yet.

2) Blindy was sploiting this earlier today

3) It's been news for a bit, and will effect almost any browser on the Windows platform if certain things are done properly.

* NullDevice kicks the server. "Floggings will continue until processing power improves!"
-----------------------------------
"That was black magic, and it was easy to use. Easy and fun. Like Legos." -- Harry Dresden
-----------------------------------
That's what playing Ragnarok Online taught me: There's no problem in the universe that can't be resolved by the proper application of daggers to faces.
Azizza
VANDERSHANKED
posted 12-12-2003 06:59:56 PM
Doesn't work in Safari or IE for Mac.
"Pacifism is a privilege of the protected"
Random Insanity Generator
Condom Ninja El Supremo
posted 12-12-2003 07:03:16 PM
quote:
Azizza was listening to Cher while typing:
Doesn't work in Safari or IE for Mac.

Please see point number 3 again.

* NullDevice kicks the server. "Floggings will continue until processing power improves!"
-----------------------------------
"That was black magic, and it was easy to use. Easy and fun. Like Legos." -- Harry Dresden
-----------------------------------
That's what playing Ragnarok Online taught me: There's no problem in the universe that can't be resolved by the proper application of daggers to faces.
Toktuk
Pooh Ogre
Keeper of the Shoulders of Peachis Perching
posted 12-12-2003 08:28:50 PM
quote:
Random Insanity Generator had this to say about pies:
3) It's been news for a bit, and will effect almost any browser on the Windows platform if certain things are done properly.

Probably more of a Windows exploit than an Internet Explorer one, then. I'm currently running a build of Firebird that's a few weeks old and it displays an incorrect URL as well. My iBook is busted right now and I don't have any Linux distros loaded at the moment - anyone who uses Firebird regularly on OS X or Linux care to test it out and let us know?

-Tok

Delphi Aegis
Delphi. That's right. The oracle. Ask me anything. Anything about your underwear.
posted 12-12-2003 08:35:44 PM
quote:
Toktuk was listening to Cher while typing:
Probably more of a Windows exploit than an Internet Explorer one, then. I'm currently running a build of Firebird that's a few weeks old and it displays an incorrect URL as well. My iBook is busted right now and I don't have any Linux distros loaded at the moment - anyone who uses Firebird regularly on OS X or Linux care to test it out and let us know?

-Tok


I have a boot disk of Knoppix.

I'm such a dumbass for posting that.

Azizza
VANDERSHANKED
posted 12-12-2003 08:36:31 PM
quote:
This insanity brought to you by Random Insanity Generator:
Please see point number 3 again.

Opps sorry man. DIdn't even see your post.

"Pacifism is a privilege of the protected"
Toktuk
Pooh Ogre
Keeper of the Shoulders of Peachis Perching
posted 12-12-2003 08:44:05 PM
quote:
Delphi Aegis had this to say about (_|_):
I have a boot disk of Knoppix.

I'm such a dumbass for posting that.


I do too, but Knoppix doesn't include Firebird. I think it's just plain old Konqueror. If they do have a Gecko browser, it's Mozilla, and I'm sure it's not a recent build.

Thus, you are worthless to me.

-Tok

Drysart
Pancake
posted 12-12-2003 10:58:00 PM
quote:
What the Random Insanity Generator??
3) It's been news for a bit, and will effect almost any browser on the Windows platform if certain things are done properly.

It will affect any browser on any platform if that browser, or the OS toolbox is written in C. Similar variants of this same well-known class of problem have plagued applications of all sorts for years.

El Cuchillo
RETARD! DO NOT FEED!
posted 12-13-2003 02:42:06 AM
OS - Debian Linux (Sarge Distro)

Browser - Mozilla Firebird 0.6.1

Result from Del's test link - http://www.evercrest.com%01%00@home.cogeco.ca/~jpaccione/ in my address bar, Del's page on my screen

That help?

Strip Club - Online Comic Reader and Archiver for Linux and Windows (and maybe OSX)
Random Insanity Generator
Condom Ninja El Supremo
posted 12-13-2003 11:31:52 AM
quote:
Drysart got all f'ed up on Angel Dust and wrote:
It will affect any browser on any platform if that browser, or the OS toolbox is written in C. Similar variants of this same well-known class of problem have plagued applications of all sorts for years.

Yeah, it's called 'Trusting user input' and it's considered acceptable for some reason.... What's wrong with a sanity check on user supplied input every now and then?

* NullDevice kicks the server. "Floggings will continue until processing power improves!"
-----------------------------------
"That was black magic, and it was easy to use. Easy and fun. Like Legos." -- Harry Dresden
-----------------------------------
That's what playing Ragnarok Online taught me: There's no problem in the universe that can't be resolved by the proper application of daggers to faces.
Zeke
I am a vampire and
posted 12-13-2003 03:40:16 PM
Aw, I was trying it out on a friend and can't get it working...
"Death most resembles a prophet who is without honor in his own land or a poet who is a stranger among his people."
"Cowards die many times before their deaths;
The valiant never taste of death but once."
Hime, eien-ni, anata-wo ai-shimasu.
Alaan
posted 12-13-2003 04:58:03 PM
So is there any danger to be found with this, or just kind of annoying?
Espio Idsavant
You have gotten better at Being a Lush! (200)
posted 12-13-2003 05:09:21 PM
quote:
Alaan had this to say about Optimus Prime:
So is there any danger to be found with this, or just kind of annoying?

Well I think trying to use it now on these boards will get you autobanned. *shrugs*

But it poses great risk for password stealing sites trying to pass themselves off as being legit, since they can make the URL in the window appear to be at aol.com, station.sony.com, whatever ... instead of being at the geocities.com url that they are really at.

And you can still be free, If time will set you free
And going higher than the mountain tops
And go high like the wind don't stop...


[ My gooberish Live Journal thingy ]

Alaan
posted 12-13-2003 05:21:07 PM
Ah. Thats true. The only thing I was thinking of before is mislabeled DL links. Note to self: Type in mail.yahoo.com etc. for a while.
diadem
eet bugz
posted 12-13-2003 06:31:52 PM
quote:
A sleep deprived Alaan stammered:
So is there any danger to be found with this, or just kind of annoying?

paypal

play da best song in da world or me eet your soul
All times are US/Eastern
Hop To: