User Name
Password

Go Back   Planetarion Forums > Non Planetarion Discussions > Programming and Discussion
Register FAQ Members List Calendar Arcade Today's Posts

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
Unread 11 Dec 2003, 13:12   #1
JetLinus
Friendly geek of GD :-/
 
JetLinus's Avatar
 
Join Date: Nov 2000
Location: On my metal roid
Posts: 923
JetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud of
Wow, this is dangerous...

It's just about Internet Explorer again, but it's been known for quite some time now, and as lot of people are using IE...

Well, you know, you can type in adresses in the format of
Code:
http://username:password@hostname
Alright, nothing new.
But if you include ASCII Char 0x01 in the part before the url, only this bit will be shown.

Example: What would you think, this link goes to:

Code:
http://pirate.planetarion.com/register.php?do=signup&[email protected]
Yeah, well, LOOKS like it would register you on the boards, including my email as referrer (some websites do this sort of thing).
Ok, that's the first glance. Good informed people know, that there can't be "@"-chars in an url. But who would mistrust that link?

In reality, it will bring you to (my non-existing imaginary) website jetworld.de
All I had to do was copy the signup page of these boards, and steal your password.

It's all shit, innit?

Try THIS link: http://www.microsoft.com. Looks like you are visiting microsoft.com, but you obviously aren't...
I know, the status bar reveals the truth, but using javascript, you could easily fake it as well...

Bad world :-/
__________________
[»] Entropy increases! :-/
JetLinus is offline   Reply With Quote
 



Forum Jump


All times are GMT +1. The time now is 00:27.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2018