lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri, 03 Aug 2007 17:48:07 +0200
From: "Michal Bucko" <michal.bucko@...ytt.com>
To: bugtraq@...urityfocus.com
Subject: [ELEYTT] 3SIERPIEN2007

Eleytt Research
www.eleytt.com


Overview:
====================
Michal Bucko, Eleytt
Shyaam Sundhar R S, Eleytt





Credit:
====================

Michal Bucko, Eleytt, www.eleytt.com/michal.bucko
Gynvael Coldwind (for providing a good example)






Vulnerability Table
===================

1. Firefox 2.0.0.6 Encoded URI Statusbar Spooing Vulnerability





Vulnerability Details
=========================
=========================




1. Firefox 2.0.0.6 Encoded URI Statusbar Spooing Vulnerability
============================================================



Firefox 2.0.0.6 is prone to statusbar spoofing, which might be
exploited by malicious attackers to conduct phishing attacks.

Here is the example:

http://www.eleytt.com/michal.bucko/Eleytt_PhishAGoGo/bucked2.html






Eleytt - Company Information
============================

Eleytt Corporation is specialized in penetration testing, vulnerability
development, advanced reverse engineering and exploitation techniques.
Eleytt provides various security-related services: risk assessment,
security policy, security assurance, incident management, web
application security testing, continuous security assurance programs.
Eleytt provides security audits for financial institutions and e-commerce.
Eleytt provides an in-depth security analysis - experienced security
experts analyze your source code, analyze your application, analyze your
web application. Eleytt runs security programs for financial institutons
and e-commerce.

We have the mission to improve the security level of software and web
applications. It is us who help you implement more secure applications.
We help you understand the risk and deploy security solutions. We help
you avoid costly business disruptions.




These are the questions, which might help you understand how we work:
=====================================================================

Want to get your web site checked for security vulnerabilities?

Your server requires real penetration testing?

Interested in Eleytt Business Continuity Program?

Interested in Eleytt Application Security Program?




For more information, please use:

www.eleytt.com





DISCLAIMER
==========


This document and all the information it contains are provided "as is",
for educational purposes only, without warranty of any kind, whether
express or implied.

The authors reserve the right not to be responsible for the topicality,
correctness, completeness or quality of the information provided in
this document. Liability claims regarding damage caused by the use of
any information provided, including any kind of information which is
incomplete or incorrect, will therefore be rejected.

Powered by blists - more mailing lists