Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] Microsoft Internet Explorer Content-Disposition HTML File Handling Flaw |
|---|---|
| Date: | Mon, 10 Apr 2006 10:22:43 -0400 |
Microsoft Internet Explorer Content-Disposition HTML File Handling Flaw April 10, 2006 Content-Disposition (defined in RFC 2183) is often used by web application developers as a mechanism to instruct the web browser on how it should handle a file download. This is commonly used to help prevent access to the application scope when handling file attachments and mitigates the ability to leverage client-side attacks, such as XSS, through file downloads. While Internet Explorer does handle downloading most file types correctly with Content-Disposition, it mishandles HTML files and instead opens them inline, exposing the application scope. As such, it is strongly advisable that web-based software vendors use alternative methods to mitigate this class of attack. A simple PoC is available at the following URL: http://xs.vc/content-disposition/ Feel free to compare the results of Firefox and IE. Vulnerable Versions: All versions up to and including Internet Explorer 7 Beta 2. References: http://www.faqs.org/rfcs/rfc2183.html http://support.microsoft.com/kb/182315/ http://msdn.microsoft.com/library/default.asp?url=/workshop/networking/moniker/overview/mime_handling.asp I felt it was necessary to make this flaw public now because while the weakness results from IEs flawed support of RFC 2183, the exposure is with the 3rd party applications which support it. Due to the simplicity of exploitation, it is not unlikely this is being used in the wild. Thank you, Darren Bounds _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Web Browser For Penetration Test, Hamed Tajabadi |
|---|---|
| Next by Date: | Re: Web Browser For Penetration Test, Justin Clarke |
| Previous by Thread: | Administrivia: FAQ?, Andrew van der Stock |
| Next by Thread: | Paros 3.2.10 Release, contact |
| Indexes: | [Date] [Thread] [Top] [All Lists] |