Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 02-13-2004, 09:40 PM   #1
kirupai
Confirmed User
 
Join Date: Aug 2003
Location: California
Posts: 894
Whats on your clipboard (Serious Stuff) IE Vulnerability

Ok go to this website:

http://www.infinitybit.com/comsec/clippy.html

As you can see it will show what is currently stored on your clipboard this a serious flaw on IE and it has been for more than 3 yeras. Now how is this dengerous... well lets say you have some sensitive data on your clipboard you visit a website it loads and it mails a form with a field from your clipboard and thats all it takes.

Solution:

Users can close this hole by changing the default Internet setting. Preferably, Microsoft
should change the default option to prompt on the Internet zone.

To close this hole in ~7 clicks: Tools, Internet Options, Security, Internet Zone,
Custom Level, Scripting, Allow paste options via scripting -> Disable.

Credits: Steven Vittitoe and Blake Sterzinger
kirupai is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 09:42 PM   #2
nofx
Too lazy to set a custom title
 
Join Date: Nov 2002
Location: Virgin Mary's womb
Posts: 16,826
smokey is going to own gfy with this now, thanks for sharing.
__________________

Often times I wonder why
There's love and hate, theres live or die.
When sickness comes I must decide:
When feelings go, theres suicide.
nofx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 09:46 PM   #3
kirupai
Confirmed User
 
Join Date: Aug 2003
Location: California
Posts: 894
Quote:
Originally posted by nofx
smokey is going to own gfy with this now, thanks for sharing.
Yeah i was afraid someone will use it against any of us, so thats why i diceded to make it public here so people know about it and can do something to protect their selfs.
kirupai is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 09:47 PM   #4
lurking
Confirmed User
 
Join Date: Jan 2004
Posts: 868
jawascript is disabled here. smokey only knows basic html tricks.
lurking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 09:56 PM   #5
Dveron
Confirmed User
 
Join Date: Dec 2002
Location: Vancouver
Posts: 2,794
Quote:
Originally posted by kirupai
Ok go to this website:

http://www.infinitybit.com/comsec/clippy.html

As you can see it will show what is currently stored on your clipboard this a serious flaw on IE and it has been for more than 3 yeras. Now how is this dengerous... well lets say you have some sensitive data on your clipboard you visit a website it loads and it mails a form with a field from your clipboard and thats all it takes.

Solution:

Users can close this hole by changing the default Internet setting. Preferably, Microsoft
should change the default option to prompt on the Internet zone.

To close this hole in ~7 clicks: Tools, Internet Options, Security, Internet Zone,
Custom Level, Scripting, Allow paste options via scripting -> Disable.

Credits: Steven Vittitoe and Blake Sterzinger
Useful post. Thanks
__________________
Adult Comics Club - Updated Bi-Daily. 60% Recurring Payouts. Exclusive Comic Content.
Dveron is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 10:14 PM   #6
Shoehorn!
Die With Your Boots On
 
Shoehorn!'s Avatar
 
Join Date: Oct 2003
Location: Hawaii
Posts: 22,872
Interesting. They don't know a damn thing with my Mac though. Windows blows.
__________________
Shoehorn! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 10:25 PM   #7
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
Quote:
Originally posted by lurking
jawascript is disabled here. smokey only knows basic html tricks.
how can u surf without js?
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 10:29 PM   #8
lurking
Confirmed User
 
Join Date: Jan 2004
Posts: 868
Quote:
Originally posted by Lane


how can u surf without js?
I dont. it is disabled on the board.
lurking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 10:31 PM   #9
fuzebox
making it rain
 
fuzebox's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: seattle
Posts: 22,119
I don't have a clipboard...
fuzebox is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 10:34 PM   #10
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
I <3 Mozilla FireFox
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 10:34 PM   #11
gleb
Confirmed User
 
Join Date: Nov 2002
Location: NY
Posts: 311
wow, thats pretty fucking serious

and before i thought address bar spoofing was hardcore
gleb is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 10:47 PM   #12
kirupai
Confirmed User
 
Join Date: Aug 2003
Location: California
Posts: 894
Quote:
Originally posted by gleb
wow, thats pretty fucking serious

and before i thought address bar spoofing was hardcore
Yeah adress spoofing is mainley used in phishing scams, they make it look more LEGIT which is a serious problem to.
kirupai is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 10:59 PM   #13
digifan
The Profiler
 
digifan's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: ICQ 76281726 and I'm female
Posts: 14,618
Quote:
Originally posted by TheSmutPeddlerDOTcom
Interesting. They don't know a damn thing with my Mac though. Windows blows.
__________________
[email protected]
Webair Rocks
digifan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 10:59 PM   #14
Mr.Fiction
Confirmed User
 
Join Date: Feb 2002
Location: Free Speech Land
Posts: 9,484
Someone used this exploit on GFY already. Good information on how to fix it.
__________________
Don't be lazy, protect free speech: ACLU | Free Speech Coalition | EFF | IMPA
Mr.Fiction is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 11:05 PM   #15
 Smokey The Bear 
So Fucking Banned
 
Join Date: Dec 2003
Location: South Of Heaven™
Posts: 3,880
Quote:
Originally posted by lurking
jawascript is disabled here. smokey only knows basic html tricks.
Your a fucking moron with no brains. This exploit has been around for the last year. Completely useless. WHy would i want your paste ?? especially when i can get most people's c:\ in here .

Also jav</b>ascript is not disabled , you just dont have the ability to use it.

<p><font size="2" face="Verdana, Arial">
__________________
<a href="http://www.sucker.com"><img src="http://bestpornhost.com/gfy/jay.png" border="0"></a>
 Smokey The Bear  is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 11:08 PM   #16
 Smokey The Bear 
So Fucking Banned
 
Join Date: Dec 2003
Location: South Of Heaven™
Posts: 3,880
And it isnt a flaw it is part of i.e. like it or hate it. Go to www.tinyurl.com and try it out.
 Smokey The Bear  is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 11:10 PM   #17
lurking
Confirmed User
 
Join Date: Jan 2004
Posts: 868
Quote:
Originally posted by *Smokey The Bear*
especially when i can get most people's c:\ in here
lol. whats mine.
lurking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 11:11 PM   #18
 Smokey The Bear 
So Fucking Banned
 
Join Date: Dec 2003
Location: South Of Heaven™
Posts: 3,880
Quote:
Originally posted by lurking


lol. whats mine.
Sorry i dont do requests.

<p><font size="2" face="Verdana, Arial">
__________________
<a href="http://www.sucker.com"><img src="http://bestpornhost.com/gfy/jay.png" border="0"></a>
 Smokey The Bear  is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 11:11 PM   #19
lurking
Confirmed User
 
Join Date: Jan 2004
Posts: 868
Quote:
Originally posted by *Smokey The Bear*


Sorry i dont do requests.
chump.
lurking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-13-2004, 11:14 PM   #20
 Smokey The Bear 
So Fucking Banned
 
Join Date: Dec 2003
Location: South Of Heaven™
Posts: 3,880
Quote:
Originally posted by lurking


chump.
No mitnick was a chump ( and a rat ) thats why he ended up in jail.
 Smokey The Bear  is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-14-2004, 12:36 AM   #21
lurking
Confirmed User
 
Join Date: Jan 2004
Posts: 868
Quote:
Originally posted by *Smokey The Bear*


No mitnick was a chump ( and a rat ) thats why he ended up in jail.
whats your point? are you trying to compare yourself to him? chump.
lurking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.