Re: [Full-disclosure] URL Spoofing vulnerability in different browsers

2011-07-23 Thread James Voss
Lol, okay -- Regards, James Voss james.v...@northwestdedicated.com LinkedIn: http://www.linkedin.com/in/jameswvoss 312-000- - Direct 847-000- - Fax PRIVILEGED AND CONFIDENTIAL: This communication, including attachments, is for the exclusive use of addressee and may contain proprietary,

[Full-disclosure] URL Spoofing vulnerability in different browsers

2011-07-22 Thread MustLive
Hello list! I want to warn you about URL Spoofing vulnerability in Mozilla Firefox, Internet Explorer, Google Chrome, Opera and other browsers. I found it long time ago, at 6th of February 2008, just after finding of built-in CSRF vulnerability in Mozilla and Firefox (it's funky CSRF attack

Re: [Full-disclosure] URL Spoofing vulnerability in different browsers

2011-07-22 Thread Gynvael Coldwind
Hey MustLive, I'm not sure if I understood your post correctly, so please correct me if I'm wrong. The thing you describe sounds similar to the thing described in the Browser Security Handbook (http://code.google.com/p/browsersec/wiki/Part3#HTTP_authentication): Amusingly, its ghost still haunts

Re: [Full-disclosure] URL Spoofing vulnerability in different browsers

2011-07-22 Thread Chris Evans
On Fri, Jul 22, 2011 at 8:36 AM, MustLive mustl...@websecurity.com.ua wrote: Hello list! I want to warn you about URL Spoofing vulnerability in Mozilla Firefox, Internet Explorer, Google Chrome, Opera and other browsers. I found it long time ago, at 6th of February 2008, just after finding of

Re: [Full-disclosure] URL Spoofing vulnerability in different browsers

2011-07-22 Thread Chris Truncer
Just ignore Mustlive. The rest of the list does. On Jul 22, 2011, at 4:08 PM, Chris Evans scarybea...@gmail.com wrote: On Fri, Jul 22, 2011 at 8:36 AM, MustLive mustl...@websecurity.com.ua wrote: Hello list! I want to warn you about URL Spoofing vulnerability in Mozilla Firefox, Internet

Re: [Full-disclosure] URL Spoofing vulnerability in different browsers

2011-07-22 Thread Mario Vilas
Don't worry, we all know MustLive is lying, as usual. On Fri, Jul 22, 2011 at 10:08 PM, Chris Evans scarybea...@gmail.com wrote: On Fri, Jul 22, 2011 at 8:36 AM, MustLive mustl...@websecurity.com.ua wrote: Hello list! I want to warn you about URL Spoofing vulnerability in Mozilla Firefox,

Re: [Full-disclosure] URL Spoofing vulnerability in different browsers

2011-07-22 Thread Michal Zalewski
Just ignore Mustlive. The rest of the list does. Well, sadly, it leads to things like this: http://www.securityfocus.com/bid/40487 /mz ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and