stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


THai's Shoutbox XSS (Spoofing URL) BUG







THai's Shoutbox XSS (Spoofing URL) BUG

THai's Shoutbox XSS (Spoofing URL) BUG 03/29/2005 03:00 PM

CorryL (Mar 27 2005)




This is a GrokNews Entry: (what is grok?)





Similar Items

THai's Shoutbox XSS (Spoofing URL) BUG

Grok Headline matches for THai's Shoutbox XSS (Spoofing URL) BUG

Webfroot Shoutbox


Webfroot Shoutbox 03/19/2005 02:38 AM
Summary of past year, and what's being done

Shoutbox Kecil


Shoutbox Kecil 03/29/2005 07:07 AM
Shoutbox kecil v0.2

New Spoofing Vulnerability in IE


New Spoofing Vulnerability in IE 12/17/2004 06:27 PM

Visual Spoofing


Visual Spoofing 02/11/2004 09:35 AM

While Microsoft recently patched a URL-based spoofing vulnerability, I just realized that a whole new class of spoofing exists for browsers: Visual Spoofing.  I have not yet seen any evidence of this type of spoofing actually being done, but I was able to create a demo within a few minutes.

Here is the demo of visual spoofing for IE6 I put together.  Note that the vulnerability is not unique to IE.

The problem with visual spoofing is that it is difficult to fix with a simple patch.  Yes there are ways to fix the problem partially but not completely because one can still create a page that looks like part of desktop by having images of overlapping windows to distract the clueless user who tend to keep many windows open.

I sure hope I don't get blamed for destroying e-commerce single-handedly with this post.  After all, the vulnerability was there in plain sight for everyone to see all this time.


Microsoft looks into Web-spoofing bug


Microsoft looks into Web-spoofing bug 12/15/2003 12:57 PM
Microsoft says it is investigating reports of a potential problem in its ubiquitous Web browser software that could allow hackers to create convincing spoofs of Web sites. The bug was reported by Secunia, a security company, and could allow hackers to display a false Web address on a fake site, making it easier for hackers to take advantage of fake "Web fronts" that purport to be a major commerce-driven site like eBay or PayPal, but actually are designed by the hacker to capture user names, passwords and financial information.

P2P Spoofing Patent?


P2P Spoofing Patent? 05/09/2004 03:26 AM

Some years ago, a collegue of mine asked me how I would stop music pirating.  I haven't thought about the problem before but it took me only a minute to decide P2P spoofing was the best intermediate answer.  It was obvious that traditional DRM wouldn't work and spoofing attacked the problem at reasonable cost, could be deployed fast, and adapt to changes in real time.  My collegue nodded and that was that.

According to Wired, someone had the exact same idea and filed a paten t in 2000.  Now I am scratching my head.  Is this a silly patent or not?  Should I be filing patents on similar ideas?  Heck, I can pump out enough ideas like that everyday to keep an army of patent lawyers busy if someone would just keep throwing problems at me and file my answers as patents.  I even have ideas on how to efficiently generate new patents.  Maybe I'll even best IBM at the game.

If you are an idle patent lawyer, come to me and I'll keep you busy.  How does 50-50 sound?  Filing cost?  No problem.  Let private investors place 'bets' on the patent applications they like out of daily streams of patent applications.  Together we'll worsen the patent problem ten-fold within a year and force the Congress to come up with a better solution.  Now that's a silver-spoon full of patriotism for ya.  :-)


IP Spoofing: Understanding the basics


IP Spoofing: Understanding the basics 05/12/2004 02:27 PM

Academics Patent P2P Spoofing


Academics Patent P2P Spoofing 05/08/2004 05:06 AM
Two computer scientists get a patent on a technique that floods peer-to-peer networks with spoofed files. They hope to sell it to content owners. Could companies that already spoof files be in violation of the patent? By Katie Dean.

Caller ID Spoofing Service


Caller ID Spoofing Service 08/31/2004 05:56 AM

My wife and I made a decision nearly 2 years ago to no longer pay for Caller ID. I was initially against it but in the long run I have not missed it. All of the important calls come in on the cell anyway. For those of you that have Caller ID a new spoofing service is out their. I would imagine for stalkers and prank callers this service will be valuable but I just don't understand why you would want to legitimately spoof your caller ID. [ZDNet]


Another IE Spoofing Hole Found


Another IE Spoofing Hole Found 01/29/2004 03:49 AM
The latest vulnerability could let an attacker hide the file extension of a malicious file download. Users can avoid the threat by saving files first.

Accessibility, jihad, spoofing


Accessibility, jihad, spoofing 04/20/2004 08:39 AM
Letters: Lexicon of discontent

Keep clear of spoofing at hotspots


Keep clear of spoofing at hotspots 03/23/2005 08:02 AM
TechWorld Mar 23 2005 10:09AM GMT

Other News: CallerID Spoofing


Other News: CallerID Spoofing 08/31/2004 06:12 AM
This nasty technology threatens to render CallerID useless, or worse....

Automated Caller ID / ANI Spoofing


Automated Caller ID / ANI Spoofing 07/09/2004 03:36 AM

Caller ID Spoofing... For Businesses


Caller ID Spoofing... For Businesses 08/27/2004 07:01 PM
Forget spoofed email headers, a new company has been set up to help companies spoof the caller ID. The product is focused at collections agencies and private investigators, who can call a deadbeat up pretending to be someone they know to get them to answer the phone. The company insists they just want to target those types of customers, but I imagine some telemarketers would enjoy using such a tool. Meanwhile, there are some questions on legality. One person notes that it doesn't appear to break any laws -- but someone else points out that there are rules against collections agencies misrepresenting themselves. And, of course, as soon as this becomes popular, someone will pass a law banning caller ID spoofing.

Spoofing XP SP2 Security Center


Spoofing XP SP2 Security Center 08/27/2004 01:52 PM

PC Magazine has dug up some evidence that the Security Center that is installed with XP Service Pack Two has a huge hole in it. If the hole is exploited it could give users a false sense of security or worse. [PC Magazine]


Microsoft investigates spoofing bug


Microsoft investigates spoofing bug 12/11/2003 06:14 AM
Silicon.com Dec 11 2003 4:46AM ET

Mozilla UI Spoofing Vulnerability


Mozilla UI Spoofing Vulnerability 07/31/2004 05:32 AM

ddress Bar Spoofing Vulnerability


ddress Bar Spoofing Vulnerability 08/19/2004 01:03 PM

Direct and Related Links for 'ddress Bar Spoofing Vulnerability'

“Software: Microsoft Internet Explorer 5.01, Microsoft Internet Explorer 5.5, Microsoft Internet Explorer 6. Liu Die Yu has discovered a vulnerability in Internet Explorer, which potentially can be exploited by malicious people to conduct phishing attacks against a user…. The vulnerability has been confirmed on a fully patched system with Internet Explorer 6 running on Microsoft Windows 2000 SP4 / Microsoft Windows XP SP1. Previous versions of Internet Explorer may also be affected. Secunia has developed…

Secunia Advisory: URL Spoofing


Secunia Advisory: URL Spoofing 12/12/2003 12:46 PM
http-equiv_at_excite.com (Dec 12 2003)

NullyFake - Site Spoofing in MSIE


NullyFake - Site Spoofing in MSIE 08/16/2004 02:20 PM
Liu Die Yu (Aug 15 2004)

Caller ID spoofing service for sale


Caller ID spoofing service for sale 09/06/2004 07:28 AM
Can't stand the heat, please buy my kitchen

MS XP SP2 Windows Security Center allows
spoofing


MS XP SP2 Windows Security Center allows
spoofing
08/27/2004 01:32 PM
Jérôme (Aug 26 2004)

Opera Patches URL-Spoofing Flaw


Opera Patches URL-Spoofing Flaw 06/03/2004 03:30 PM
The browser's shortcut icon feature could be manipulated to trick Web surfers into revealing personal information.

Notes and Tips: Browser Spoofing


Notes and Tips: Browser Spoofing 07/07/2004 11:17 AM
A cure might be worse than the illness....

Forward:FullDisclosure/IE - Possible
Address Spoofing


Forward:FullDisclosure/IE - Possible
Address Spoofing
07/23/2004 12:51 PM
Liu Die Yu (Jul 22 2004)

Netscape Java Tab Spoofing Vulnerability


Netscape Java Tab Spoofing Vulnerability 08/27/2004 05:41 PM

Direct and Related Links for 'Netscape Java Tab Spoofing Vulnerability'

“J. Courcoul has discovered a vulnerability in Netscape, which can be exploited by malicious people to conduct phishing attacks….

Re: Mozilla Firefox Certificate Spoofing


Re: Mozilla Firefox Certificate Spoofing 07/27/2004 04:35 PM
Chris Brown (Jul 27 2004)

The Impact of RFC Guidelines on DNS
Spoofing Attacks


The Impact of RFC Guidelines on DNS
Spoofing Attacks
07/15/2004 03:10 PM
have2Banonymous (Jul 12 2004)

RE: Forward:FullDisclosure/IE - Possible
Address Spoofing


RE: Forward:FullDisclosure/IE - Possible
Address Spoofing
07/27/2004 04:35 PM
Chenghuai Lu (Jul 26 2004)

Service offers spoofing of caller ID


Service offers spoofing of caller ID 08/31/2004 04:43 AM
ZDNet UK Aug 31 2004 8:51AM GMT

Mozilla Firefox Certificate Spoofing


Mozilla Firefox Certificate Spoofing 07/26/2004 04:07 PM
E.Kellinis (Jul 25 2004)

RE: The Impact of RFC Guidelines on DNS
Spoofing Attacks


RE: The Impact of RFC Guidelines on DNS
Spoofing Attacks
07/19/2004 09:50 AM
have2Banonymous (Jul 18 2004)

Apple Blocks IDN Spoofing in Safari


Apple Blocks IDN Spoofing in Safari 03/22/2005 04:24 PM
Following in the footsteps of Mozilla and Opera, Apple has issued its monthly Mac OS X security update with a fix for the spoofing vulnerability caused by Internationalized Domain Names. Apple's Safari Web browser will now only display URL characters from an approved list, which can be customized by the user.

Detailed Information on IE address bar
spoofing


Detailed Information on IE address bar
spoofing
05/07/2004 03:29 AM
Hackers have been tricking Internet Explorer to show the wrong address for a long time which has tricked some people...

Internet Explorer URL Spoofing
Vulnerability


Internet Explorer URL Spoofing
Vulnerability
12/19/2003 11:24 AM
This information has made the rounds already but a few of you have sent me e-mail asking about the vulnerability...

Re: phpBB 2.0.8a and lower - IP spoofing
vulnerability


Re: phpBB 2.0.8a and lower - IP spoofing
vulnerability
04/19/2004 05:57 PM
Shaun Colley (Apr 19 2004)

Dialog Origin Spoofing Vulnerability


Dialog Origin Spoofing Vulnerability 06/22/2005 02:41 AM

Secunia Research has discovered this security vulnerability in several web browsers, including Safari and Internet Explorer on Mac. The vulnerability “…can be exploited by malicious web sites to spoof dialog boxes. The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open e.g. a prompt dialog box, which appears to be from a trusted site. Successful exploitation normally requires that a user is tricked into…

Direct and Related Links for 'Dialog Origin Spoofing Vulnerability'


phpBB 2.0.8a and lower - IP spoofing
vulnerability


phpBB 2.0.8a and lower - IP spoofing
vulnerability
04/19/2004 03:02 PM
Ready Response (Apr 18 2004)
Grok Description matches for THai's Shoutbox XSS (Spoofing URL) BUG
GrokA matches for THai's Shoutbox XSS (Spoofing URL) BUG

THai's Shoutbox XSS (Spoofing URL) BUG

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

Stinky ROV from
Phoenix Takes on MIT

Court Case Could
Rewrite Copyright
Rules

IconLover v2.15
Supreme Court Weighs
Internet
File-Sharing Case
(Reuters)

Microsoft CRM: Buy
Now or Wait?
(NewsFactor)

Microsoft Bows to EU
Demands on Windows
Media Player
(NewsFactor)

Failsafe:
Enterprise-Class
Wireless Storage
(NewsFactor)

Microsoft hopeful of
accord with EU on
media-free Windows
version (AFP)

Dow Jones Executive
Foresees More Paid
Web Sites (Reuters)

Fresh First-Person
Shooters Released
(AP)

Supreme Court Weighs
in on File-Sharing
(AP)

Secret Service Using
Distributed
Computing to Break
Encryption

Apple: Security
Update 2005-003
(Server) 1.1

Poll: Harvard
Students Mostly
Unhappy (AP)

Will Fargo Display
Fiberglass Bison?
(AP)

La. Judge Doesn't Go
Far for Jury Duty
(AP)

Cop Suspended for
Ticketing Doctor on
Call (AP)

Alabama Boy Drives
Off in Father's
Truck (AP)

Too Sleepy for Sex?
(Reuters)

Should your blog
have a business?

PHP Dev Studio
Advanced Server
Control Panel

ReleaseForge
JuleOS Dynamite
RealTimeBattle
pyPYME
Supreme Court takes
hard look at P2P

Best Buy To Sell Mac
mini In Stores?

Mac OS X 10.4
(8A425) - Final
Candidate?

Album review: Beck's
"Guero"

About that budding
democracy

Jesse Jackson to the
rescue -- but whose?

The aid swindle
The undiplomatic
diplomat

Apprehension in
Alaska

Whiskery stem cells
grow skin, muscles
and neurons

Verizon finds $1bn
more for MCI

Passenger screening
gimmick stuck at the
gate

IBM server breaks
time - marketing
continuum to tie
Dell to market

HP bets on the Hurd
mentality for CEO

Bush Says He Expects
New Iraqi Government
Soon (Reuters)

Tribal Leader's Son
Arrested in
Minnesota Shootings
(Reuters)

MCI accepts Verizon
bid of $7.64 billion

HP said to pick
NCR's Hurd as new
CEO

HP jumps on 64-bit
Xeon wagon

CA puts forgotten
IDs in crosshairs
with acquisition

CEOs confident in
continued growth

Planetwide Games to
Host "Golden Launch"
Event For RYL: Path
of the Emperor Video
Game at Digital
Hollywood

Web Crossing adds
Content Blob
Management

Spiderweb releases
Geneforge 3 game

what is grok?