Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Mozilla Firefox cross domain access

  Mozilla Foundation Security Advisory 2007-07

  [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability

  Firefox: about:blank is phisher's best friend

  Firefox: serious cookie stealing / same-domain bypass vulnerability

From:Michal Zalewski <lcamtuf_(at)_DIONE.IDS.PL>
Date:15.02.2007
Subject:Re: [Full-disclosure] Firefox: serious cookie stealing / same-domain bypass vulnerability

On Thu, 15 Feb 2007, pdp (architect) wrote:

> I wander whether we can execute code on about:config or about:cache.

Actually, there are several odd problems related to location updates and
location.hostname specifically, including one scenario that apparently
makes the script run with document.location in about: namespace.

I did not research them any further, so I can't say if they're
exploitable - but you can see a demo here, feel free to poke around:

 http://lcamtuf.coredump.cx/fftests.html

Cheers,
/mz
http://lcamtuf.coredump.cx/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru