[Full-disclosure] Re: Browzar Footprints

Dave "No, not that one" Korn davek_throwaway at hotmail.com
Tue Sep 5 14:49:29 BST 2006


lsi wrote:
> If the user uses Browzar's default search page, it's obvious as hell:
>
> 2xx.206.1x6.1x5 - - [01/Sep/2006:20:49:19 +0100] "GET
> /parvati/ici_bse.htm HTTP/1.1" 200 18754
> "http://www.browzar.com/search/browzar.asp?q=david%20brown%20prion"
> "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"

  <evil>  Why don't you set your server to automatically 302 any client with 
a browzar.com referer header to one of the pages about how useless browzar 
is ?

    cheers,
      DaveK

n.b. closing /evil tag omitted on purpose.  i plan to stay this way. 
muahahahahaaaa!
-- 
Can't think of a witty .sigline today.... 






Full-Disclosure is hosted and sponsored by Secunia.