hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

what
exploit example is here. Not really an exploit, but could be more useful if I could insert a redirect script in a yahoo e-mail. I read up on the -- exploit before tags and <form> tag exploits, but I don't think that they work. Anyways, I want to try to use scripting from inside of .jpeg files, like some I've seen on this site. If someone could point me in the right direction, it would be greatly appreciated. Maybe some links to examples or something like that.

Well, the link above will take you to my server at home, and display http://www.mail.yahoo.com as your location. I've changed the script for the page also. Instead of encrypting the info in md5, it just posts the information to my server logs in plain text. It was something that I just kind of started out of bordom, and grew from there. Thanks for any help ahead of time, I just thought this was somewhat interesting.
nibbler
QUOTE (what @ Mar 2 2004, 01:29 PM)
Well, the link above will take you to my server at home, and display http://www.mail.yahoo.com as your location.



REALLY?


user posted image
Paul
Av is showing up, "url spoofing", guess im upto date wink.gif
invisible-boy
hi,
this is Address spoofer,this bug for IE,Netscape & other browser,
but don't need use many  us can use:
http://www.address.com+alt+0160+@+address
for ex:
http://mail.yahoo.com @microsoft.com
good luck.
tweakz20
yeah that's a good idea.. don't know how many people it would trick if they actually look at the address bar though...
chaat_sleuth
QUOTE (invisible-boy @ Mar 2 2004, 04:33 PM)
hi,
this is Address spoofer,this bug for IE,Netscape & other browser,
but don't need use many  us can use:
http://www.address.com+alt+0160+@+address
for ex:
http://mail.yahoo.com @microsoft.com
good luck.

This vunlnerability was patched on 2004-02-02 by removing support for usernames and passwords in URLs.

h++p://www.microsoft.com/technet/security/bulletin/MS04-004.asp
buzzons
it however still works for FTP so if you can make the FTP show as HTTP then it will be fine wink.gif

JeiAr
http://www.gulftech.org/03012004.php

Using some of the recent IE faws you could probably use that to grab passwords remotely.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.