[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Browser address bar characters into a small feature
# Published : 2010-02-12
# Author : Pouya Daneshmand
# Previous Title : Internet Explorer 8 (Multitudinous looping )Denial of Service Exploit
# Next Title : Radasm v2.2.1.6 .rap file Local Buffer Overflow PoC
#################################################################
# Securitylab.ir
#################################################################
# Application Info:
# Name: Internet Explorer
# Version: 8.0
# Other tested browsers that also automatically convert "" to "/":
# - Firefox v3.6
# - Google Chrome 4.0.249.78 (36714)
#################################################################
Vulnerability: (IE address bar characters into a small feature)
My IE 8 on the address bar will automatically enter the url of the "" (0x5c) transformed into "/" (0x2f)
Example: www.securitylab.ir<http://www.securitylab.ir> a Converted www.securitylab.ir/a<http://www.securitylab.ir/a>
Recently found that some phishing sites take advantage of this feature to bypass some security checks, it is hereby to be a mark
#################################################################
# Discoverd By: Pouya Daneshmand
# Website: http://securitylab.ir
# Contacts: admin[at]securitylab.ir & whh_iran[AT]yahoo.com
###################################################################