Whats on your clipboard (Serious Stuff) IE Vulnerability

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • kirupai
    Confirmed User
    • Aug 2003
    • 894

    #1

    Whats on your clipboard (Serious Stuff) IE Vulnerability

    Ok go to this website:

    http://www.infinitybit.com/comsec/clippy.html

    As you can see it will show what is currently stored on your clipboard this a serious flaw on IE and it has been for more than 3 yeras. Now how is this dengerous... well lets say you have some sensitive data on your clipboard you visit a website it loads and it mails a form with a field from your clipboard and thats all it takes.

    Solution:

    Users can close this hole by changing the default Internet setting. Preferably, Microsoft
    should change the default option to prompt on the Internet zone.

    To close this hole in ~7 clicks: Tools, Internet Options, Security, Internet Zone,
    Custom Level, Scripting, Allow paste options via scripting -> Disable.

    Credits: Steven Vittitoe and Blake Sterzinger
  • nofx
    Too lazy to set a custom title
    • Nov 2002
    • 16826

    #2
    smokey is going to own gfy with this now, thanks for sharing.

    Often times I wonder why
    There's love and hate, theres live or die.
    When sickness comes I must decide:
    When feelings go, theres suicide.

    Comment

    • kirupai
      Confirmed User
      • Aug 2003
      • 894

      #3
      Originally posted by nofx
      smokey is going to own gfy with this now, thanks for sharing.
      Yeah i was afraid someone will use it against any of us, so thats why i diceded to make it public here so people know about it and can do something to protect their selfs.

      Comment

      • lurking
        Confirmed User
        • Jan 2004
        • 868

        #4
        jawascript is disabled here. smokey only knows basic html tricks.

        Comment

        • Dveron
          Confirmed User
          • Dec 2002
          • 2794

          #5
          Originally posted by kirupai
          Ok go to this website:

          http://www.infinitybit.com/comsec/clippy.html

          As you can see it will show what is currently stored on your clipboard this a serious flaw on IE and it has been for more than 3 yeras. Now how is this dengerous... well lets say you have some sensitive data on your clipboard you visit a website it loads and it mails a form with a field from your clipboard and thats all it takes.

          Solution:

          Users can close this hole by changing the default Internet setting. Preferably, Microsoft
          should change the default option to prompt on the Internet zone.

          To close this hole in ~7 clicks: Tools, Internet Options, Security, Internet Zone,
          Custom Level, Scripting, Allow paste options via scripting -> Disable.

          Credits: Steven Vittitoe and Blake Sterzinger
          Useful post. Thanks
          Adult Comics Club - Updated Bi-Daily. 60% Recurring Payouts. Exclusive Comic Content.

          Comment

          • Shoehorn!
            Die With Your Boots On
            • Oct 2003
            • 22872

            #6
            Interesting. They don't know a damn thing with my Mac though. Windows blows.

            Comment

            • Lane
              Will code for food...
              • Apr 2001
              • 8496

              #7
              Originally posted by lurking
              jawascript is disabled here. smokey only knows basic html tricks.
              how can u surf without js?

              Comment

              • lurking
                Confirmed User
                • Jan 2004
                • 868

                #8
                Originally posted by Lane


                how can u surf without js?
                I dont. it is disabled on the board.

                Comment

                • fuzebox
                  making it rain
                  • Oct 2003
                  • 22369

                  #9
                  I don't have a clipboard...

                  Comment

                  • goBigtime
                    Confirmed User
                    • Nov 2002
                    • 7761

                    #10
                    I <3 Mozilla FireFox

                    Comment

                    • gleb
                      Confirmed User
                      • Nov 2002
                      • 311

                      #11
                      wow, thats pretty fucking serious

                      and before i thought address bar spoofing was hardcore

                      Comment

                      • kirupai
                        Confirmed User
                        • Aug 2003
                        • 894

                        #12
                        Originally posted by gleb
                        wow, thats pretty fucking serious

                        and before i thought address bar spoofing was hardcore
                        Yeah adress spoofing is mainley used in phishing scams, they make it look more LEGIT which is a serious problem to.

                        Comment

                        • digifan
                          The Profiler
                          • Oct 2002
                          • 14618

                          #13
                          Originally posted by TheSmutPeddlerDOTcom
                          Interesting. They don't know a damn thing with my Mac though. Windows blows.
                          [email protected]
                          Webair Rocks

                          Comment

                          • Mr.Fiction
                            Confirmed User
                            • Feb 2002
                            • 9484

                            #14
                            Someone used this exploit on GFY already. Good information on how to fix it.
                            Don't be lazy, protect free speech: ACLU | Free Speech Coalition | EFF | IMPA

                            Comment

                            •  Smokey The Bear 
                              So Fucking Banned
                              • Dec 2003
                              • 3880

                              #15
                              Originally posted by lurking
                              jawascript is disabled here. smokey only knows basic html tricks.
                              Your a fucking moron with no brains. This exploit has been around for the last year. Completely useless. WHy would i want your paste ?? especially when i can get most people's c:\ in here .

                              Also jav</b>ascript is not disabled , you just dont have the ability to use it.

                              <p><font size="2" face="Verdana, Arial">
                              __________________
                              <a href="http://www.sucker.com"><img src="http://bestpornhost.com/gfy/jay.png" border="0"></a>

                              Comment

                              •  Smokey The Bear 
                                So Fucking Banned
                                • Dec 2003
                                • 3880

                                #16
                                And it isnt a flaw it is part of i.e. like it or hate it. Go to www.tinyurl.com and try it out.

                                Comment

                                • lurking
                                  Confirmed User
                                  • Jan 2004
                                  • 868

                                  #17
                                  Originally posted by  Smokey The Bear 
                                  especially when i can get most people's c:\ in here
                                  lol. whats mine.

                                  Comment

                                  •  Smokey The Bear 
                                    So Fucking Banned
                                    • Dec 2003
                                    • 3880

                                    #18
                                    Originally posted by lurking


                                    lol. whats mine.
                                    Sorry i dont do requests.

                                    <p><font size="2" face="Verdana, Arial">
                                    __________________
                                    <a href="http://www.sucker.com"><img src="http://bestpornhost.com/gfy/jay.png" border="0"></a>

                                    Comment

                                    • lurking
                                      Confirmed User
                                      • Jan 2004
                                      • 868

                                      #19
                                      Originally posted by  Smokey The Bear 


                                      Sorry i dont do requests.
                                      chump.

                                      Comment

                                      •  Smokey The Bear 
                                        So Fucking Banned
                                        • Dec 2003
                                        • 3880

                                        #20
                                        Originally posted by lurking


                                        chump.
                                        No mitnick was a chump ( and a rat ) thats why he ended up in jail.

                                        Comment

                                        • lurking
                                          Confirmed User
                                          • Jan 2004
                                          • 868

                                          #21
                                          Originally posted by  Smokey The Bear 


                                          No mitnick was a chump ( and a rat ) thats why he ended up in jail.
                                          whats your point? are you trying to compare yourself to him? chump.

                                          Comment

                                          Working...