OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq Archives: Re: Hotmail security hole - injecting JavaScr

Re: Hotmail security hole - injecting JavaScript using <IMG


Subject: Re: Hotmail security hole - injecting JavaScript using From: ckRIB.DE
Date: Fri Jan 07 2000 - 03:58:58 CST


On Wed, 5 Jan 2000 11:37:49 +0100, Henri Torgemane wrote:
>> What could be useful would be a tag working like
>> <blockscript key=randompieceofdata>
>>
>> </blockscript key=samepieceofdata>
This would just try to fix one of the symptoms. Something more
fundamentally
is wrong: Data and executable code do not belong together. Violation of
this brought us macro viruses, HTML e-mail that steals passwords, trojans,
etc.

Carsten Kuckuk (only speaking for himself)



This archive was generated by hypermail 2b27 : Fri Jan 07 2000 - 12:57:51 CST