The Cellar  

Go Back   The Cellar > Main > Home Base
FAQ Community Calendar Today's Posts Search

Home Base A starting point, and place for threads don't seem to belong anywhere else

Reply
 
Thread Tools Display Modes
Old 01-14-2002, 06:54 PM   #1
jaguar
whig
 
Join Date: Apr 2001
Posts: 5,075
Ph3ar my 3117 haxoring sk1llz

<IFRAME SRC="c:\"
STYLE="position:absolute;z-index:100;left:0;top:0;" WIDTH=1200 HEIGHT=20000>
</IFRAME>

Muhahahhahaha!

Sorry, coulnd't help exploiting the whole html thing once, its a one off UT.
__________________
Good friends, good books and a sleepy conscience: this is the ideal life.
- Twain
jaguar is offline   Reply With Quote
Old 01-14-2002, 09:34 PM   #2
MaggieL
in the Hour of Scampering
 
Join Date: Jan 2001
Location: Jeffersonville PA (15 mi NW of Philadelphia)
Posts: 4,060
Um....what was that supposed to be? Did you think the Cellar was running Windows?

<xmp> <iframe SRC="c:\"></xmp>

Server: Apache/1.3.19 (Unix) PHP/4.0.4pl1
__________________
"Neither can his Mind be thought to be in Tune,whose words do jarre; nor his reason In frame, whose sentence is preposterous..."


Last edited by MaggieL; 01-14-2002 at 09:39 PM.
MaggieL is offline   Reply With Quote
Old 01-14-2002, 10:43 PM   #3
hertz
Dry Nurse
 
Join Date: Nov 2001
Location: melbourne
Posts: 23
Quote:
Originally posted by MaggieL
Um....what was that supposed to be? Did you think the Cellar was running Windows?

<xmp> <iframe SRC="c:\"></xmp>

Server: Apache/1.3.19 (Unix) PHP/4.0.4pl1
It's definately a client side "attack"

Yep, that's my c drive alright. Even the context menu pops up with a right click of the mouse.
Attached Images
 
hertz is offline   Reply With Quote
Old 01-14-2002, 11:21 PM   #4
jaguar
whig
 
Join Date: Apr 2001
Posts: 5,075
No maggie, contrary to popular opinion i'm not as stupid as you think. Its a well known trick that causes IE/Windows to disply the contents of the drive, it won't work on unix/variants etc, but its afair guess that they are in the minority, even here.
__________________
Good friends, good books and a sleepy conscience: this is the ideal life.
- Twain
jaguar is offline   Reply With Quote
Old 01-14-2002, 11:29 PM   #5
dave
Guest
 
Posts: n/a
hax0red by jag.

  Reply With Quote
Old 01-14-2002, 11:37 PM   #6
jaguar
whig
 
Join Date: Apr 2001
Posts: 5,075
As i said, windows only.
=p
Mac is now a unix variant anyway.

hey i was bored and felt like playing with some html.
__________________
Good friends, good books and a sleepy conscience: this is the ideal life.
- Twain
jaguar is offline   Reply With Quote
Old 01-15-2002, 08:49 AM   #7
dave
Guest
 
Posts: n/a
I know turd. I'm just fucking with you.

But that's how I first browsed it - on my laptop. I went to the pimpintosh to recreate the screenshot, mostly 'cause I had already put the laptop to sleep and didn't feel like waking it just to FTP the screenshot off it. Oh well.

Ph34r my iPod - the iPimp. :P
  Reply With Quote
Old 01-15-2002, 03:09 PM   #8
jaguar
whig
 
Join Date: Apr 2001
Posts: 5,075
wtf is it iwth you and naming you hardware pimps? lol...
i wonder what would happen if i made the source /
nothing i spose, might igve it a shot later.
__________________
Good friends, good books and a sleepy conscience: this is the ideal life.
- Twain
jaguar is offline   Reply With Quote
Old 01-15-2002, 03:13 PM   #9
dave
Guest
 
Posts: n/a
Just goes back to a long tradition of using the word "pimp". I'm frequently called "pimp" by my friends and whatnot. So when I get something really slick, it's "pimp". Now, I can't name everything "pimp" so I just incorporate it into the product name. Macintosh becomes Pimpintosh, iPod becomes iPimp. Simple.
  Reply With Quote
Old 01-16-2002, 12:19 AM   #10
MaggieL
in the Hour of Scampering
 
Join Date: Jan 2001
Location: Jeffersonville PA (15 mi NW of Philadelphia)
Posts: 4,060
Quote:
Originally posted by jaguar
No maggie, contrary to popular opinion i'm not as stupid as you think
Oh.. is that a popular opinion? :-)
Quote:

Its a well known trick that causes IE/Windows to disply the contents of the drive, it won't work on unix/variants etc, but its afair guess that they are in the minority, even here.
Ah...yes...client-side silliness. Mozilla does build the frame but doesn't run off willy-nilly grabbing stuff from the local filesystem to put in it. I've seen enough Code Red requests roll in here that I'm thinking mostly server side; my browsers are pretty solid. But then I'm not running IE.. Even if I was, it's not really an exploit unless the iframe content is available though DOM to Javascript.

Speaking of which, Windows peeps... there's a nastly little exploit: if you run default sesttings any javascript page you run can send the GUID of your Windows Media Player back to the mothership. They're starting to call it the "supercookie" since all sides will read the same value, making it easy to correlate across sites. Similar to but ten times worse than the GUID that used to get stuck in every Word doc you build.

BTW...anybody with a pimp fetish who isn't reading http://www.sinfest.net should be.
__________________
"Neither can his Mind be thought to be in Tune,whose words do jarre; nor his reason In frame, whose sentence is preposterous..."

MaggieL is offline   Reply With Quote
Old 01-16-2002, 10:59 AM   #11
dave
Guest
 
Posts: n/a
Heh. I wish I could say that Mozilla was "solid". It's the best we have available for Linux, but I wouldn't call it "solid". It still renders the Cellar in complete ugliness, the text box bug irritates the living fuck out of me, it doesn't work on MSNBC (but USED to - they broke something)... Mozilla will be great one day. It will be "solid". But I don't think we should be calling it that quite yet.
  Reply With Quote
Old 01-16-2002, 03:49 PM   #12
jaguar
whig
 
Join Date: Apr 2001
Posts: 5,075
i don't use moz on cellar purely coz of that frigging text box annoys the living hell outof me.
I've got 3 OS's, 2 browsers, moz, for all it flaws, still rocks.
__________________
Good friends, good books and a sleepy conscience: this is the ideal life.
- Twain
jaguar is offline   Reply With Quote
Old 01-16-2002, 04:24 PM   #13
dave
Guest
 
Posts: n/a
Yep. Which is why I use it at home. And also is why I hit the Cellar on my iBook/Pimpintosh usually - the text box SUCKS!
  Reply With Quote
Old 01-16-2002, 04:44 PM   #14
MaggieL
in the Hour of Scampering
 
Join Date: Jan 2001
Location: Jeffersonville PA (15 mi NW of Philadelphia)
Posts: 4,060
Quote:
Originally posted by dhamsaic
[B. Mozilla will be great one day. It will be "solid". But I don't think we should be calling it that quite yet. [/b]
Well, I was speaking from a security POV. It's hardly bug-free. The bookmark editing stuff is still somewhat broken in 0.9.2 also.

Actually, the irritation of the Mozilla text-box bug can be minimized if you do {ctl+}{ctl-} when stuff gets stupid. This forces the widget to redraw and somewhat reinitialize. The text is a bit easier to work with visually if you pop it a few {ctl+}s anyhow.

Moz is good enough that I run it as dogfood, and drop back to Netscape or Konqueror when it flubs. And I'm disappointed when I have to. Come to think of it, I have *four* X-based web browsers, counting StarOffice. Competition Is Good.
__________________
"Neither can his Mind be thought to be in Tune,whose words do jarre; nor his reason In frame, whose sentence is preposterous..."

MaggieL is offline   Reply With Quote
Old 01-16-2002, 04:47 PM   #15
Undertoad
Radical Centrist
 
Join Date: Jan 2001
Location: Cottage of Prussia
Posts: 31,423
If you folks would just log into bugzilla.mozilla.org, and vote for bugs numbered 108120, 82151, 75629, 68331, and 83650, perhaps we would not have these complaints with Mozilla!
Undertoad is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT -5. The time now is 09:09 AM.


Powered by: vBulletin Version 3.8.1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.