RE: Internet explorer 7.0 spoofing

2008-04-02 Thread Mike Diaz
He's basically saying that if you create a popup small enough
width-wise, then you can hide everything before the # so that unless
the user actually goes into the address bar and scrolls left, all they
will see is what you put after the #. Here's a screenshot so you can
see what he's talking about:
http://lh6.google.com/mikediaz.360/R_PpsHN-hCI/ABc/_F2JZMpUiS4/Screenshot.png


Re: Re: Re: Internet explorer 7.0 spoofing

2008-04-02 Thread jplopezy
Dear w0lfd33m: 


Not fail in firefox, these poorly understood failure. 

The fault is not that they are both directions numeral (#) if it is that when 
you create a popup with this small sample size the end of the address complete 
numeral only makes what is behind it is irrelevant to the The first address, 
then create the popup which is only the end of the address is the address false 
and there is failure. This only works in Internet Explorer. 



Greetings. 




RE: Internet explorer 7.0 spoofing

2008-04-02 Thread Darth Jedi
Ok, I'm missing it, what exactly is the spoof here?  When the popup comes up
for me, the address of the page is
http://www.google.com.ar/#www.microsoft.com and I see in the address bar
#www.microsoft.com.  

If I'm understanding the wording below correctly, it's because the # keeps
the browser from interpreting Microsoft.com and thus giving a bad URL, and
presumably, the browser cannot or does not have the ability to show the full
address (and perhaps in other browsers or scenarios people don't see the #
like I did - and also don't realize that the browser always prefixes it's
URLs with HTTP, so seeing a URL starting with # is a bit fishy)...






-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] 
Sent: Friday, March 28, 2008 3:02 PM
To: bugtraq@securityfocus.com
Subject: Internet explorer 7.0 spoofing

Hello, as they are? This time I communicate with you to let you know of a
vulnerability such as "spoofing" in the Internet Explorer 7.0 (tested at 8.0
and does not work). 

Creating a pop-up malformated can put any address in the address bar in the
body any page or content. 


This flaw is possible because if in the address bar we eg 


Address # direction 


The numeral makes the first address is run and what comes after the numeral
does not interfere with the original page. This is why creating popup with
the special measures and to try to pass such an easterly direction popup
displayed the end of the address and did not show the direction it runs.
(Special measures are important because if it does not work largest). 


Just a single click in the body popup to this reveals the true direction,
which can be equal to dodge an event like javascript onblur or onfocus ..
Anyway that's more serious an attack that a proof of concept. 


Here I leave the proof of concept.


http://es.geocities.com/jplopezy/iespoof.html


Greetings from Argentina!


Juan Pablo Lopez Yacubian

fuzzertina.blogspot.com


No virus found in this incoming message.
Checked by AVG. 
Version: 7.5.519 / Virus Database: 269.22.1/1347 - Release Date: 3/27/2008
7:15 PM
 

No virus found in this outgoing message.
Checked by AVG. 
Version: 7.5.519 / Virus Database: 269.22.3/1354 - Release Date: 4/1/2008
5:38 AM
 



Re: Re: Internet explorer 7.0 spoofing

2008-04-01 Thread w0lfd33m
I too tested on the same version of Firefox but it worked in my case! What 
address did you use as main URL. Was it google.com?

You can find the snap of the spoofed URL captured in Firefox here: 
hxxp://img249.imageshack.us/my.php?image=spoofzg2.png


Re: Internet explorer 7.0 spoofing

2008-04-01 Thread Razi Shaban
Doesn't work on FF3.0b1 or b2.


On 3/29/08, mouss <[EMAIL PROTECTED]> wrote:
> [EMAIL PROTECTED] wrote:
>  > This problem is not specific to IE. It works on Firefox too.
>  >
>
>
> just tested on FF 2.0.0.13 and it doesn't work.
>
>
>


Re: Internet explorer 7.0 spoofing

2008-03-31 Thread mouss

[EMAIL PROTECTED] wrote:

This problem is not specific to IE. It works on Firefox too.
  


just tested on FF 2.0.0.13 and it doesn't work.




Re: Internet explorer 7.0 spoofing

2008-03-29 Thread w0lfd33m
This problem is not specific to IE. It works on Firefox too.