[4535] in WWW Security List Archive

home help back first fref pref prev next nref lref last post

Re: Question about User Identity (CGI scripting)

daemon@ATHENA.MIT.EDU (Greg Goddard)
Thu Feb 20 15:44:29 1997

Date: Thu, 20 Feb 1997 12:47:38 -0500
To: "Brian W. Spolarich" <briansp@ans.net>
From: Greg Goddard <fjord@ce.ufl.edu>
Cc: www-security@ns2.rutgers.edu
Errors-To: owner-www-security@ns2.rutgers.edu

At 09:12 AM 2/19/97 -0500, you wrote:
>  What they're doing isn't particularly exciting or complex.  Essentially,
>they're running a simple CGI program that, based on your IP address, does
>a few things:

In addition to running a script to check variables, the site in question
<http://www.anonymizer.com> is doing the old javascript trick: hiding
a form and mailing it to themselves. (see http://www.anonymizer.com/snoop.pl)

Greg


home help back first fref pref prev next nref lref last post