evolve or die

ieTrick.txt

ieTrick.txt
Posted Dec 31, 2004
Authored by Albert Puigsech Galicia

Internet Explorer will accept %0a and %0d in URLs. In FTP URLs, it will accept them in the username part of the URL. Due to the similarity between the FTP and SMTP protocols, this can be used to send mail.

tags | advisory, protocol
MD5 | ee66b2e6d49b546793170520a819053e

ieTrick.txt

Change Mirror Download

--5mCyUwZo2JvN/JJP
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Product: Microsoft Internet Explorer
Version: 6.0.2800.1106, 6.0.2900

Product: Microsoft Outlook Express
Version: 6 SP1 Win2K (reported by Brian Bruns)

Description:
Internet Explorer can be tricked into sending mail through its FTP
client without any more user interaction than loading a page.

Details:
Internet Explorer will accept %0a and %0d in URLs. In FTP URLs, it will
accept them in the username part of the URL. Due to the similarity
between the FTP and SMTP protocols, this can be used to send mail.

Danger:
Spammers could host websites that contain images causing website
visitors to spam more people. There are probably other protocols that
the FTP client could be used to maliciously access.

Example:
http://dsbl.org/testingground/IE-FTP-SMTP-link/

Fix:
Connections to port 25 should be blocked (ala lynx) and newline
characters, post-decoding, shouldn't be accepted in places where they
represent protocol delimiters.

Vendor notification:
None; patch would be attached if this was free software.

Credit:
Thanks to Albert Puigsech Galicia (http://www.7a69ezine.org/) for the
initial idea. Thanks to John Prendergast and Mike Venzke for help
testing. Thanks to Fred Smith for warnings of doom and destruction
resulting from this.

--=20
Ian Gulliver
Penguin Hosting
"Failure is not an option; it comes bundled with your Microsoft products."

--5mCyUwZo2JvN/JJP
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD4DBQFBy1skefI+qeoOjxURAsUQAJd+oyx2/9KO/1NHL1eWQl5/c0RuAJ0ShB1Q
ZlhW3JVqhCr5lEPg/55CNg==
=FLUW
-----END PGP SIGNATURE-----

--5mCyUwZo2JvN/JJP--

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close