Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Multiple Browser URI Display Obfuscation Weakness

No exploit required. The researcher who discovered this issue has setup a demonstration page that can be accessed via the following link:

http://www.zapthedingbat.com/security/ex01/vun1.htm

A second proof of concept URI has been provided by http-equiv <1@malware.com> which is designed to also place tab characters after the hexadecimal 1 value, which will hide a malicious site from the task bar as well. http-equiv has also made an online demo available which can be obtained below. The PoC URI is as follows:

<A href="http://www.microsoft.com%01%09%09%09%09%09%09%09@www.malware.com">religious software</A>

Guy Crumpley has supplied a utility (URL-Obfuscator-Page-Creator.vbs) designed to generate pages to exploit this vulnerability.







 

Privacy Statement
Copyright 2008, SecurityFocus