umm tested this you dont need %01 either
btw.
was messing around with some hex stile as well is
there a way to call a file:// inside a http:// becos the issue with doing the @
trick is it appends http:// automaticly, mind you , u could just make it exec
some vb code or something on a site, just a random idea any way
and it dont also seem to work if you use hex as
well for the full domain ie
where as if you [EMAIL PROTECTED] works
----- Original Message -----
|
Title: RE: FWD: Internet Explorer URL parsing vulnerability
- Re: Re: [Full-Disclosure] RE: FWD: Internet Exp... Clint Bodungen
- Re: [Full-Disclosure] RE: FWD: Internet Explorer URL ... S . f . Stover
- Re: [Full-Disclosure] RE: FWD: Internet Explorer URL ... S G Masood
- Re: [Full-Disclosure] RE: FWD: Internet Explorer... Michal Zalewski
- Re: [Full-Disclosure] RE: FWD: Internet Expl... Nick FitzGerald
- Re: [Full-Disclosure] RE: FWD: Internet Explorer... Clint Bodungen
- Re: [Full-Disclosure] RE: FWD: Internet Expl... Nick FitzGerald
- RE: [Full-Disclosure] RE: FWD: Internet Expl... Chris S
- Re: [Full-Disclosure] RE: FWD: Internet Explorer... Clint Bodungen
- [Full-Disclosure] RE: FWD: Internet Explorer URL pars... Julian HO Thean Swee
- Re: [Full-Disclosure] RE: FWD: Internet Explorer... VeNoMouS
- Re: [Full-Disclosure] RE: FWD: Internet Expl... S G Masood
- Re: [Full-Disclosure] RE: FWD: Internet ... VeNoMouS
- Re: [Full-Disclosure] RE: FWD: Inter... Valdis . Kletnieks
- Re: [Full-Disclosure] RE: FWD: Inter... Cedric Blancher
- Re: [Full-Disclosure] RE: FWD: Inter... S G Masood
- Re: [Full-Disclosure] RE: FWD: ... VeNoMouS
- Re: [Full-Disclosure] RE: FWD: Internet ... VeNoMouS
- RES: [Full-Disclosure] RE: FWD: Internet Exp... Cleber P. de Souza
- Re: [Full-Disclosure] RE: FWD: Internet Explorer URL ... VeNoMouS