[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAOuH4p06C-FjbqAejJ9_9suHcer3ai-H4JD0fWcNBxMp3UspTA@mail.gmail.com>
Date: Wed, 28 Nov 2012 12:00:09 +0100
From: Guifre <guifre.ruiz@...il.com>
To: Bogdan Calin <bogdan@...netix.com>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: The email that hacks you
Hello,
"I can also confirm that this attack works on iPhone, iPad and Mac's
default mail client."
Of course, it works anywhere where arbitrary client-side code can be
executed... IMAHO, the issue here is not your iphone loading images,
there are millions of attack vectors to trigger this attack... The
problem is the CSRF weaknesses of your router admin panel that should
be fixed by synchronizing a secret token or by using any other well
known mitigation strategy against these attacks.
Best Regards,
Guifre.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists