[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <8a6b8e350710070103p12d407abq893079bb1bb1745e@mail.gmail.com>
Date: Sun, 7 Oct 2007 01:03:09 -0700
From: "James Matthews" <nytrokiss@...il.com>
To: Geo. <geoincidents@....net>
Cc: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: Re: URI handling woes in Acrobat Reader, Netscape,
Miranda, Skype
there have always been these vluns
On 10/6/07, Geo. <geoincidents@....net> wrote:
>
> ----- Original Message -----
> From: "Thierry Zoller" <Thierry@...ler.lu>
>
> > The user clicks on a mailto link, is that untrusted code?
>
> Depends on where the link comes from. If it's a shortcut on the users
> desktop no it's not untrusted, if it's in a PDF file you received in your
> email then yes it's untrusted.
>
> > Anyways, the mailto link
> > POST IE7 has a flaw/threat/vulnerablity it hasn't had PRE IE7.
>
> > The problem here is the root cause, the root cause is that IE7
>
> Ok I'm game, so then show me this exploit without having Acrobat on your
> system. IE7 handles mailto links in untrusted web pages. Put the mailto
> link
> in an untrusted html page and make it work with IE7.
>
> Geo.
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
--
http://www.goldwatches.com/mens/cufflinks.html
http://www.jewelerslounge.com
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists