[<prev] [next>] [day] [month] [year] [list]
Message-ID: <q2m2d6724811004221143md7566ebbof40d857ffd59dc27@mail.gmail.com>
Date: Thu, 22 Apr 2010 14:43:27 -0400
From: T Biehn <tbiehn@...il.com>
To: Dan Kaminsky <dan@...para.com>
Cc: Full disclosure <full-disclosure@...ts.grok.org.uk>
Subject: Re: IE8 img tag HiJacking
Hey, you actually posted information! Congrats!
Did you learn about this 'information channel' from your numerous 'blackhat'
friends?
-Travis
On Apr 22, 2010 2:17 PM, "Dan Kaminsky" <dan@...para.com> wrote:
Also, Billy Hoffman has done a lot of fun work in this space, see
http://www.gnucitizen.org/blog/javascript-remoting-dangers/
2010/4/22 Dan Kaminsky <dan@...para.com>:
> Interesting use, using filesize to back into the actual CAPTCHA used for a
> given query. Sneaky!...
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists