GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   New IE Bug Hides Real Site Address - Are you vulnerable? (https://gfy.com/showthread.php?t=207466)

quantum-x 12-11-2003 04:10 PM

New IE Bug Hides Real Site Address - Are you vulnerable?
 
Read about this one.. it's actually pretty nasty!

It allows people to fake what displays up in the location bar, while the browser points somewhere else...

TEST here

Read the advisories here

I wonder how long it'll take for people to start using https://secure-russian-billing.com :/

quantum-x 12-11-2003 04:12 PM

Check the test link above. It links offsite, but the browser even thinks it's going to the spoofed site - and only shows that i the status bar.

This is more than slghtly nasty!

Dirty F 12-11-2003 04:13 PM

Im safe...

Using Opera.

 Smokey The Bear  12-11-2003 04:24 PM

What part of " I.E. " in the thread title didnt you get battuss ?

gornyhuy 12-11-2003 04:30 PM

Shit!

Now how can I make money from this?

Dirty F 12-11-2003 04:32 PM

Quote:

Originally posted by *Smokey The Bear*
What part of " I.E. " in the thread title didnt you get battuss ?
What part of im safe, im using Opera didnt you get idiot?

Stop fucking stalking me...youre like shit under my shoe that just wont go.

Fucking freak.

404 12-11-2003 04:45 PM

holy fuck... :helpme

quantum-x 12-11-2003 04:46 PM

Quote:

Originally posted by Battuss


What part of im safe, im using Opera didnt you get idiot?

Stop fucking stalking me...youre like shit under my shoe that just wont go.

Fucking freak.

heeere we go :D

Lane 12-11-2003 05:30 PM

Quote:

Originally posted by gornyhuy
Shit!

Now how can I make money from this?


spam those fake paypal emails, and the address will look real :Graucho

Lensman 12-11-2003 05:33 PM

Good one.

Mr.Fiction 12-11-2003 05:34 PM

How long will it take someone to blame Smokey The Bear for this? :1orglaugh

ThunderBalls 12-11-2003 05:38 PM

Quote:

Originally posted by gornyhuy
Shit!

Now how can I make money from this?

Thats what I was thinking! :1orglaugh

ThunderBalls 12-11-2003 05:40 PM

Netscape 7.1 is also vulnerable to this.

404 12-11-2003 05:58 PM

shit, there don't seem to be any work-arounds yet either, although right-click/properties on the link shows the offending character.

i'm guessing the phishers are doing overtime on their fake sites at the moment.

JSA Matt 12-11-2003 06:03 PM

It doesn't work with sites that redirect / break out of frames.. like cnn.com

Nice find though

JSA Matt 12-11-2003 06:04 PM

Quote:

Originally posted by Lane
spam those fake paypal emails, and the address will look real :Graucho
It works with paypal.com too : )

Test: <a href="http://www.adult.com%[email protected]/">Adult.com</a> :winkwink:

TheJimmy 12-11-2003 06:05 PM

Quote:

Originally posted by ThunderBalls
Netscape 7.1 is also vulnerable to this.

I just hit their test link and my NS 7.1 didn't get exploited...

in-ter-esting...


only sounds worthwhile to <><'ers & carders...

$5 submissions 12-11-2003 06:09 PM

Quote:

Originally posted by Mr.Fiction
How long will it take someone to blame Smokey The Bear for this? :1orglaugh
LOL. Seriously, somebody should hire him as a security expert. Dude's got skillz.

gleb 12-11-2003 06:12 PM

haha thats cool :thumbsup

now u've made me extra paranoid

NoAngel 12-11-2003 06:14 PM

More Vuln. of IE

Liu Die Yu - Chinese IT Expert

fuzebox 12-11-2003 06:25 PM

So how does it look under IE? I still see the site, but the full URL is shown in the address bar (fakeurl + garbage characters + @real url etc)...

In the status bar I see the fake url + a garbage character.

Does this all look clean and unassuming under IE? Everything after (and including) the garbage character hidden?

If so, nice.

funkmaster 12-11-2003 06:33 PM

Quote:

Originally posted by Lane



spam those fake paypal emails, and the address will look real :Graucho

... this got me started !!

420 12-11-2003 06:50 PM

looks alot of people are going to get scammed this christmas :(

quantum-x 12-11-2003 06:53 PM

Quote:

Originally posted by fuzebox
So how does it look under IE? I still see the site, but the full URL is shown in the address bar (fakeurl + garbage characters + @real url etc)...

In the status bar I see the fake url + a garbage character.

Does this all look clean and unassuming under IE? Everything after (and including) the garbage character hidden?

If so, nice.

http://kweks.brisurbex.com/mei/uploads/iebug.gif

looks coche all the way, even when you move your mouse over the link :/

Dildozer 12-11-2003 06:57 PM

haha my first thought was also sending someone at goatse.cx

quantum-x 12-11-2003 06:59 PM

Quote:

Originally posted by Dildozer
haha my first thought was also sending someone at goatse.cx
I think that's a call out for people to make the funniest fake url w/ the ie bug competition :D

lEricPl 12-11-2003 07:10 PM

It looks like all it does is use a line break to seperate the URL.

microsoft.com%[email protected]/internet_explorer_address_bar_spoofing_test/

The URL is basically on 2 lines.

This does not just effect IE.

NoAngel 12-11-2003 07:17 PM

Just check your personal 'ignore list', after a redirect with my IE got some new entries there :(

Jman69 12-11-2003 07:25 PM

Sure enough my IE failed the test, with netscape it added a bunch of extra characters to the url.

Its shit like this that makes me glad netscape is my default browser.

NoAngel 12-11-2003 07:26 PM

Quote:

Originally posted by Jman69
Sure enough my IE failed the test, with netscape it added a bunch of extra characters to the url.

Its shit like this that makes me glad netscape is my default browser.

:thumbsup - thinking about it this moment

quantum-x 12-11-2003 07:43 PM

Quote:

Originally posted by Jman69
Sure enough my IE failed the test, with netscape it added a bunch of extra characters to the url.

Its shit like this that makes me glad netscape is my default browser.

yeah, pity that the 90% of people out thhere don't do the same thing..

pamphage 12-11-2003 08:28 PM

wow. thats the scariest thing i've seen in awhile. even i might have fallen for it in an email scam or something had they caught me at a bad time.

well once again ie has proven once again to be the new pioneer into gaping security holes. im suprised this one wasn't found sooner. smokey must have been wasting too much time lurking on gfy ;)

Swanks 12-11-2003 08:31 PM

Quote:

Originally posted by Mr.Fiction
How long will it take someone to blame Smokey The Bear for this? :1orglaugh
:1orglaugh :1orglaugh

pamphage 12-11-2003 08:39 PM

wow this is fun to freak out your friends and family. you can tell them you are a l33t haxx0r and you took over yahoo.com

<a href="http://www.yahoo.com%[email protected]/">Yahoo</a>

rowan 12-12-2003 12:35 AM

I notice that google's toolbar shows the PR for the fake URL, rather than the actual site it's loading. I guess this will happen with most plugins coded in C, since it will see the %00 as a string terminator.

Bigjohn 12-12-2003 12:45 AM

I typically do a view source to veryfiy any link that wants me to enter personal info. Guess my paranoia is finally paying off :uhoh

Theo 12-12-2003 12:51 AM

Quote:

Originally posted by JSA Matt


It works with paypal.com too : )

Test: <a href="http://www.adult.com%[email protected]/">Adult.com</a> :winkwink:


Alex bought adult.com :glugglug



isn't it crazy that after all these years nobody had noticed this bug?

Why 12-12-2003 12:52 AM

this exploit has been around for many many years and is not going anywhere, its for hahahahahading usernames and passwords into URLS.

JulianSosa 12-12-2003 12:56 AM

Quote:

Originally posted by Why
this exploit has been around for many many years and is not going anywhere, its for hahahahahading usernames and passwords into URLS.
Wrong.


But why the hell did some one post this

TurboTrucker 12-12-2003 01:05 AM

Very interesting

<a href="http://www.flowersandsunshine.com%[email protected]/">flowersandsunshine.com</a>


All times are GMT -7. The time now is 08:46 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123