BugTraq
Security Advisory for ALL forum services with client-set images Dec 22 2004 10:03AM
James Bandara (jamez1 gmail com) (2 replies)
Re: Security Advisory for ALL forum services with client-set images Dec 23 2004 08:50AM
Stefan Paletta (stefanp cabal1 com)
James Bandara wrote/schrieb/scripsit:
>To block this I suggest you edit your service to only accept links that
>end in image formats for images before the querystring.

That doesn't really help â?? the attacker can send a HTTP redirect from an
innocent-looking URL.

-Stefan
--
junior guru SP666-RIPE JID:stefanp (at) jabber.de.cw (dot) net [email concealed] SMP@IRC

[ reply ]
Re: Security Advisory for ALL forum services with client-set images Dec 23 2004 12:52AM
Tim Jackson (lists timj co uk)


 

Privacy Statement
Copyright 2010, SecurityFocus