
![]() |
JasonD
Seeing the
Apachevuln thread I wondered if others are also interested in security talk ?I am deeply into the "reverse engineering with a goal" method of thinking, and generally that goal is to get visitors to a site to do something for me. The biggest hurdle to this is normally the cross domain policies that are in force for Ajaxstyle comms.On that note, and to start discussions off, I wonder if any of you have played with the old (partially patched) mhtml: flaw in IE and if so your thoughts with it ? mhtml:http://www.theregister.co.uk Ask one of your IE using visitors to get that page for you ![]() And to keep Perk scared, IPhones' and other Safari based browsers aren't much better !http://www.businessinfo.co.uk/labs/SafariBetaZeroDay/safaribetazeroday.html vsloathe
I think pretty much the best thing ever was when IE would execute code stored in images. I pretty much gave myself root to a shitload of boxes that day. Looking back, not very smart. At the time though, I thought it was rather clever, since the first thing I did was to implement some sneaky changes to the HOSTS file and a little DNS/ARP poisoning. You can probably fill in the blanks here as to how to make money with those methods.
Sorry, your mention of that mhtml vulnerability brought back some memories. EDIT: Er...root...sorry - "admin" as windows calls it. perkiset
LOL @ JD - the
iPhones do have some well documented potential vectors, but thus far you'd have to do some somewhat extraordinary things on both my side and their side to break in.eWeek also had a pretty scathing article about the potentials for hacking, but their proclivities are well known: just today I got the article "Blackberry 8820 a Dream Device" right after I got the " iPhoneis massive security risk" email. They're like the Republicans of technology![]() But I'm also good with discussions about security, provided we don't publicly cross any lines that would be unseemly. If there's something too edgy I'll place it ... "Up There" ![]() /p JasonD
The gig 89a image thing was wonderful
![]() Perk - got ya |

Thread Categories

![]() |
![]() |
Best of The Cache Home |
![]() |
![]() |
Search The Cache |
- Ajax
- Apache & mod_rewrite
- BlackHat SEO & Web Stuff
- C/++/#, Pascal etc.
- Database Stuff
- General & Non-Technical Discussion
- General programming, learning to code
- Javascript Discussions & Code
- Linux Related
- Mac, iPhone & OS-X Stuff
- Miscellaneous
- MS Windows Related
- PERL & Python Related
- PHP: Questions & Discussion
- PHP: Techniques, Classes & Examples
- Regular Expressions
- Uncategorized Threads