[26196] in bugtraq

home help back first fref pref prev next nref lref last post

Re: AIM forced behavior "issue"

daemon@ATHENA.MIT.EDU (=?iso-8859-1?Q?Knud_Erik_H=F8jgaar)
Tue Jul 16 17:54:35 2002

Message-ID: <005801c10e38$2b059c70$24029dd9@ssss>
From: =?iso-8859-1?Q?Knud_Erik_H=F8jgaard?= <kain@egotrip.dk>
To: "orb" <orb@mindflip.org>, <bugtraq@securityfocus.com>
Date: Mon, 16 Jul 2001 22:44:53 +0200
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

> Example
> <META
>
HTTP-EQUIV="refresh"CONTENT=0;URL=aim:addbuddy?listofscreennames=mindfliporg
,mfliporb,mflipmax,mflips0nic,mflipzorcon&groupname=mindfliporg>
>
> A web page loaded with the above code in it's META REFRESH tag would
> automatically add a group to the users buddylist called mindfliporg and
> add buddy's
> mindfliporg, mfliporb, mflipmax, mflips0nic, mflipzorcon to the group.

We tried some similar stuff with icq a while ago, live example at
http://knudergud.dk/dev/icq.html ..
it seems broken now, but the idea should be obvious. adding to a contact
list using javascript, requiring
no user interaction.. stupid software.

-Knud


home help back first fref pref prev next nref lref last post