[Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype

James Matthews nytrokiss at gmail.com
Sun Oct 7 09:03:09 BST 2007


there have always been these vluns

On 10/6/07, Geo. <geoincidents at nls.net> wrote:
>
> ----- Original Message -----
> From: "Thierry Zoller" <Thierry at Zoller.lu>
>
> > The user clicks on a mailto link, is that untrusted code?
>
> Depends on where the link comes from. If it's a shortcut on the users
> desktop no it's not untrusted, if it's in a PDF file you received in your
> email then yes it's untrusted.
>
> > Anyways, the mailto link
> > POST IE7 has a flaw/threat/vulnerablity it hasn't had PRE IE7.
>
> > The problem here is the root cause, the root cause is that IE7
>
> Ok I'm game, so then show me this exploit without having Acrobat on your
> system. IE7 handles mailto links in untrusted web pages. Put the mailto
> link
> in an untrusted html page and make it work with IE7.
>
> Geo.
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>



-- 
http://www.goldwatches.com/mens/cufflinks.html
http://www.jewelerslounge.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20071007/12445858/attachment.html 


Full-Disclosure is hosted and sponsored by Secunia.