"sysimage://" protocol

Discussion in 'HTML' started by Jan Faerber, Dec 9, 2004.

  1. Jan Faerber

    Jan Faerber Guest

    Jan Faerber, Dec 9, 2004
    #1
    1. Advertising

  2. Jan Faerber

    Richard Guest

    Jan Faerber wrote:

    > http://crapware.lx.ro/junkcode/security/ie-sp1-sysimage-local-file-existe
    > nce.htm


    > I don't undestand this ^^^^


    > <blockquote
    > site="http://www.securityfocus.com/archive/1/383622/2004-12-06/2004-12-12
    > /0"> Proof Of Concept
    > ================


    > <img src="sysimage://C:\WINNT\Notepad.exe,666"
    > onLoad="document.write('<b>Cannot Find File!</b>');"
    > onError="document.write('<b>File Exists!</b>');">
    > </blockquote>


    > onError => File Exists?


    Apparently testing to see if his scheme works or not.
    He's looking at "your" computer's files to see if you have notepad or not.
    But for some reason, his thinking is backwards.

    http://secunia.com/advisories/13396/
     
    Richard, Dec 9, 2004
    #2
    1. Advertising

  3. Jan Faerber

    Jan Faerber Guest

    Richard wrote:

    > Jan Faerber wrote:
    >
    > >

    http://crapware.lx.ro/junkcode/security/ie-sp1-sysimage-local-file-existe
    > > nce.htm

    >
    > > I don't undestand this ^^^^

    >
    > > <blockquote
    > >

    site="http://www.securityfocus.com/archive/1/383622/2004-12-06/2004-12-12
    > > /0"> Proof Of Concept
    > > ================

    >
    > > <img src="sysimage://C:\WINNT\Notepad.exe,666"
    > > onLoad="document.write('<b>Cannot Find File!</b>');"
    > > onError="document.write('<b>File Exists!</b>');">
    > > </blockquote>

    >
    > > onError => File Exists?

    >
    > Apparently testing to see if his scheme works or not.
    > He's looking at "your" computer's files to see if you have notepad or not.
    > But for some reason, his thinking is backwards.


    Obviously not dyslexia.


    >
    > http://secunia.com/advisories/13396/


    hm - so you can use that form on crapware.1x.ro only with
    --
    Jan

    http://linux.janfaerber.com
     
    Jan Faerber, Dec 9, 2004
    #3
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. neelesh

    USB Protocol

    neelesh, Apr 23, 2004, in forum: VHDL
    Replies:
    0
    Views:
    691
    neelesh
    Apr 23, 2004
  2. Gopi

    point to point protocol

    Gopi, Jul 13, 2004, in forum: VHDL
    Replies:
    1
    Views:
    499
    Mike Treseler
    Jul 13, 2004
  3. VHDL_lover

    CAN bus protocol

    VHDL_lover, Oct 24, 2004, in forum: VHDL
    Replies:
    6
    Views:
    12,328
    Preetam
    Nov 1, 2006
  4. Joachim Smit
    Replies:
    2
    Views:
    1,023
    Joachim Smit
    Apr 23, 2004
  5. Replies:
    0
    Views:
    707
Loading...

Share This Page