lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <8a6b8e350710070103p12d407abq893079bb1bb1745e@mail.gmail.com>
Date: Sun, 7 Oct 2007 01:03:09 -0700
From: "James Matthews" <nytrokiss@...il.com>
To: Geo. <geoincidents@....net>
Cc: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: Re: URI handling woes in Acrobat Reader, Netscape,
	Miranda, Skype

there have always been these vluns

On 10/6/07, Geo. <geoincidents@....net> wrote:
>
> ----- Original Message -----
> From: "Thierry Zoller" <Thierry@...ler.lu>
>
> > The user clicks on a mailto link, is that untrusted code?
>
> Depends on where the link comes from. If it's a shortcut on the users
> desktop no it's not untrusted, if it's in a PDF file you received in your
> email then yes it's untrusted.
>
> > Anyways, the mailto link
> > POST IE7 has a flaw/threat/vulnerablity it hasn't had PRE IE7.
>
> > The problem here is the root cause, the root cause is that IE7
>
> Ok I'm game, so then show me this exploit without having Acrobat on your
> system. IE7 handles mailto links in untrusted web pages. Put the mailto
> link
> in an untrusted html page and make it work with IE7.
>
> Geo.
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>



-- 
http://www.goldwatches.com/mens/cufflinks.html
http://www.jewelerslounge.com

Content of type "text/html" skipped

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ