The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


SV: Serious Security Hole in Hotmail


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Tue, 25 Aug 1998 20:14:07 +0200
From: Jonathan James <james@MBOX304.SWIPNET.SE>
To: BUGTRAQ@netspace.org
Subject: SV: Serious Security Hole in Hotmail

Hello everybody.
I studied Mr. Cervenka's e-mail and then started to experiment.
There is a way to do this to a browser that has Javascripting disabled.
Just put a META REFRESH tag into the htmlfile, the URL should point to the
URL which contains the actual capturing and sending of the password/login.
This is shown in an example below.
<html>
<meta http-equiv="refresh" content="1;
url=the-url-that-is-to-be-pointed-to">
and so on.....

Thankyou for your time.

Regards
Jonathan James

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру