GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Internet Explorer - cookie theft issue ? (https://gfy.com/showthread.php?t=740254)

SmokeyTheBear 06-06-2007 11:33 PM

Internet Explorer - cookie theft issue ?
 
Can some i.e. users please try this test
(firefox users dont bother , this doesnt affect firefox )

http://com.webspacemania.com/cookie/ ( perfectly safe cookie test )

thanks..

Chio 06-06-2007 11:44 PM

Using IE7 it doesn't seem to do anything

It opens a new tab that says Testing !!!!!!! Please wait until this window closes

It never does. Tried twice.

=] EVIL [= 06-06-2007 11:45 PM

bblastvisit=1179986576; bblastactivity=0; bbthread_lastview=e4c3b376e073001097cafe29c1460a26 a-10-stbp7Bi-739697_i-1181156397_i-739411_i-1181120809_i-739945_i-1181136415_i-740160_i-1181173468_i-740067_i-1181172497_i-740149_i-1181173184_i-740154_i-1181173505_i-740108_i-1181172757_i-739995_i-1181188604_i-740254_i-1181198000_stbp7D

Donkey Punch 06-06-2007 11:45 PM

would this have anything to do with :

Quote:

A race condition when navigating to a new site from a page can be exploited to perform certain actions and access the contents of the newly loaded page with the permissions of the old page.
:}

Donkey Punch 06-06-2007 11:46 PM

Quote:

Originally Posted by =] EVIL [= (Post 12559354)
bblastvisit=1179986576; bblastactivity=0; bbthread_lastview=e4c3b376e073001097cafe29c1460a26 a-10-stbp7Bi-739697_i-1181156397_i-739411_i-1181120809_i-739945_i-1181136415_i-740160_i-1181173468_i-740067_i-1181172497_i-740149_i-1181173184_i-740154_i-1181173505_i-740108_i-1181172757_i-739995_i-1181188604_i-740254_i-1181198000_stbp7D

Internet Explorer 6 ?

SmokeyTheBear 06-06-2007 11:48 PM

Quote:

Originally Posted by Chio (Post 12559349)
Using IE7 it doesn't seem to do anything

It opens a new tab that says Testing !!!!!!! Please wait until this window closes

It never does. Tried twice.

takes about 2 mins .. max ,

zeruel 06-06-2007 11:52 PM

seems fine with me on IE7...

SmokeyTheBear 06-06-2007 11:54 PM

Quote:

Originally Posted by Donkey Punch (Post 12559355)
would this have anything to do with :



:}

yes......

SmokeyTheBear 06-06-2007 11:55 PM

Quote:

Originally Posted by zeruel (Post 12559393)
seems fine with me on IE7...

how do you mean fine ?

SmokeyTheBear 06-06-2007 11:57 PM

firefox users can try this test ( only for friefox )

http://gfy.webspacemania.com/firefox/

=] EVIL [= 06-07-2007 12:00 AM

WT_FPC=id=21212f8dbea623402c71139209895703:lv=1139 209909843:ss=1139209895703

Donkey Punch 06-07-2007 12:10 AM

I fear SmokeyTheBear. I'll make sure to never get on your bad side big guy.

:)

quantum-x 06-07-2007 12:13 AM

copy pasted from
http://seclists.org/fulldisclosure/2007/Jun/0026.html

which was on slashdot 2 days ago

SmokeyTheBear 06-07-2007 12:25 AM

Quote:

Originally Posted by quantum-x (Post 12559489)
copy pasted from
http://seclists.org/fulldisclosure/2007/Jun/0026.html

which was on slashdot 2 days ago

actually someone icq'd it to me , that wasn't really the point , the test grabs your gfy cookie if possible and posts using your name in this thread if succesfull , just trying to guage what browsers working/os and such

p..s i dont think i ever pointed out an exploit that i didnt copy from somwhere or another. well thats not entirely true but 99% of them i cut and paste

SmokeyTheBear 06-07-2007 12:29 AM

Quote:

Originally Posted by quantum-x (Post 12559489)
copy pasted from
http://seclists.org/fulldisclosure/2007/Jun/0026.html

which was on slashdot 2 days ago

p.s.
the name "EVIL" above is the bot name that if the cookie grab didnt contain enough info will post a partial cookie ( not including password ) onto gfy to show the results of what it did grab.

Chio 06-07-2007 12:33 AM

The makings for thousands of zangos! :(

SmokeyTheBear 06-07-2007 12:33 AM

Quote:

Originally Posted by quantum-x (Post 12559489)
copy pasted from
http://seclists.org/fulldisclosure/2007/Jun/0026.html

which was on slashdot 2 days ago

btw i wouldnt start questioning my abilities !!! i haxored some butter with a hot knife today so i'm feeling rather saucy :winkwink:

Donkey Punch 06-07-2007 12:34 AM

Very interesting experiment STB !! :)

=] EVIL [= 06-07-2007 12:42 AM

wtf wtf hmm

=] EVIL [= 06-25-2007 08:20 AM

Hi Smokey


All times are GMT -7. The time now is 11:52 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123