lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
From: rlanguy at hotmail.com (Lan Guy) Subject: " * " in url In IE6 SP1 I see it passed to a new broswer window then everything before the last * is cut. But that would not be foolproofing it http://rd.yahoo.com/hotjbs/*http://example.com Does the exact same and abit of testing lets you conclude that rd probably stands for redirect go to yahoo!'s homepage and Look under: Yahoo! Premium Services you will see: Personal Web Site ? Sports Audio both of these function the same way Lan Guy ----- Original Message ----- From: "morning_wood" <se_cur_ity@...mail.com> To: <full-disclosure@...ts.netsys.com> Sent: Tuesday, January 13, 2004 9:30 AM Subject: [Full-Disclosure] " * " in url > dunno if this is new but.. > > http://pa.yahoo.com/*http://rd.yahoo.com/hotjbs/*http://example.com > > > m.wood > > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.netsys.com/full-disclosure-charter.html >
Powered by blists - more mailing lists