|
BugTraq
Security Advisory for ALL forum services with client-set images Dec 22 2004 10:03AM James Bandara (jamez1 gmail com) (2 replies) Re: Security Advisory for ALL forum services with client-set images Dec 23 2004 12:52AM Tim Jackson (lists timj co uk) |
|
Privacy Statement |
>To block this I suggest you edit your service to only accept links that
>end in image formats for images before the querystring.
That doesn't really help â?? the attacker can send a HTTP redirect from an
innocent-looking URL.
-Stefan
--
junior guru SP666-RIPE JID:stefanp (at) jabber.de.cw (dot) net [email concealed] SMP@IRC
[ reply ]