Graal Forums  

Go Back   Graal Forums > General Forums > Graal Main Forum (English)
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 04-27-2004, 09:07 PM
GrowlZ1010 GrowlZ1010 is offline
defunct
Join Date: May 2002
Posts: 187
GrowlZ1010 is on a distinguished road
Quote:
Originally Posted by busyrobot
Secondary question:
This 'steal your cookie by an evil link' thing - does that use special browser HTML/JS/ETC or is it all serverside?
A known Internet Explorer bug (read: glaring security hole - still around in 5.5 with all the latest Windows Update patches, not sure about 6) allows you to steal cookies using simple JavaScript - all you'd need is for someone to visit a page laced with the deadly cookie-bewildering toxin and their cookies for ANY domain anywhere can be acquired. The exploit doesn't even need to be visible to the user - the script could be run in the background in a tiny IFRAME and the user would have no idea their cookies had been compromised. A serverside script is often used to record this acquired data, but I'm not aware of any major cross-browser exploits which operate on the serverside alone.

Whether or not this was the method used in this particular situation, I am uncertain. Of course, corrections or clarifications would be welcomed.

(first post in months! hooray!)
Reply With Quote
  #2  
Old 04-28-2004, 04:33 AM
Tyhm Tyhm is offline
Psionic Youth
Tyhm's Avatar
Join Date: Mar 2001
Location: Babord, West Graal Deaths:1009 Kills:1
Posts: 5,635
Tyhm has a spectacular aura about
That's an excellent explanation of the problem. Thanks Growlz.
__________________
"Whatever," said Bean, "I was just glad to get out of the toilet."

"Power does not corrupt. Fear corrupts, perhaps the fear of a loss of power."- John Steinbeck
"I'm only acting retarded, what's your excuse?" queried the Gord.
- My pet, the Levelup Gnome

http://forums.graalonline.com/forums...&postcount=233
Reply With Quote
  #3  
Old 04-28-2004, 06:28 PM
Loriel Loriel is offline
Somewhat rusty
Loriel's Avatar
Join Date: Mar 2001
Posts: 5,059
Loriel is a name known to allLoriel is a name known to allLoriel is a name known to allLoriel is a name known to all
Quote:
Originally Posted by GrowlZ1010
known Internet Explorer bug
So Firefox/Linux wins! Weeeh!
Reply With Quote
  #4  
Old 04-28-2004, 08:08 PM
Kristi Kristi is offline
Bowie's Deciple
Kristi's Avatar
Join Date: Dec 2003
Location: Boston, MA
Posts: 748
Kristi has a spectacular aura aboutKristi has a spectacular aura about
Send a message via AIM to Kristi Send a message via MSN to Kristi
Quote:
Originally Posted by Loriel
So Firefox/Linux wins! Weeeh!
Hense the reason it wasnt that bug, but an XSS one as i explained eariler, its not browser specific =p
__________________
Reply With Quote
  #5  
Old 04-28-2004, 08:51 PM
GrowlZ1010 GrowlZ1010 is offline
defunct
Join Date: May 2002
Posts: 187
GrowlZ1010 is on a distinguished road
Quote:
Originally Posted by Kristi
Hense the reason it wasnt that bug, but an XSS one as i explained eariler, its not browser specific =p
How very interesting. I suppose that the PHP $_REQUEST array (made up of all values sent by the user - ones sent in the URL, stuff POSTed by a form, and cookie data) was being used in these scripts instead of a specific global dealing with wherever the input should be coming from, allowing for falsified cookie or POSTed values to be passed along in the URL. Or, say, cookie-stealin' JavaScript. But that's just a semi-educated guess.

As I stated previously, corrections and clarifications are always good. Instead of knowing only about the cookie vulnerability which was actually used, we now know about two! And knowing more is usually better than knowing less.

(However, I'll agree with Loriel's point just because it's dangably valid. Hooray for Firefox!)
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 02:59 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.