Re: [Full-disclosure] DoS attacks on email clients via protocol handlers

2010-06-13 Thread Eduardo Vela
MustLive Since I saw you mentioned http://www.mozilla.org/security/announce/2010/mfsa2010-23.html I think it would be important for you to know the difference between that vulnerability and yours. The reason that was fixed, was because it's generally considered safe to embed images pointing off s

Re: [Full-disclosure] DoS attacks on email clients via protocol handlers

2010-06-13 Thread Eduardo Vela
errr/ So that attack could allow an attacker to annoy millions of people with email client popups when they receive an email/visit facebook. it's important to note that the attack was in a redirection, so it's asuming the website ensured that the starting URL was https?:// -- Eduardo On Sat,

[Full-disclosure] DoS attacks on email clients via protocol handlers

2010-06-06 Thread MustLive
Hello Full-Disclosure! I want to warn you about security vulnerabilities in email clients, particularly in Outlook Express and Outlook. This advisory is concerned with my series of advisories about vulnerabilities in browsers, which belong to group of DoS via protocol handlers. All those who doub