[41361] in bugtraq

home help back first fref pref prev next nref lref last post

Re: XSS on Yahoo Mail

daemon@ATHENA.MIT.EDU (Matan Peled)
Sat Nov 26 15:06:00 2005

Message-ID: <4388998A.7010307@gmail.com>
Date: Sat, 26 Nov 2005 19:21:14 +0200
From: Matan Peled <chaosite@gmail.com>
Reply-To: chaosite@gmail.com
MIME-Version: 1.0
To: little.hacker@gmail.com
Cc: bugtraq@securityfocus.com
In-Reply-To: <20051124124826.3405.qmail@securityfocus.com>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit

little.hacker@gmail.com wrote:
> yea there is bug but it seems url doesn't work correctly.

Thats actually because you wrote:

<a href="littlehacker ...

instead of:

<a href="http://littlehacker ...

Try it like that and see it work =)

-- 
[Name      ]   ::  [Matan I. Peled    ]
[Location  ]   ::  [Israel            ]
[Public Key]   ::  [0xD6F42CA5        ]
[Keyserver ]   ::  [keyserver.kjsl.com]
encrypted/signed  plain text  preferred


home help back first fref pref prev next nref lref last post