Saturday, February 13, 2010

Fred Williams


I ran across a pretty interesting article on RSnake's blog about using a URL to get users to disclose personal information. Here is the original article:

I tested this in IE8 and the posting claims it works in IE6 and IE7 as well.  I tested in Firefox with and without NoScripts enabled and it doesn't work.  Yay Firefox!

What you can do is to embed text in a URL surrounded by the normal % % that will grab the actual value out of the system value and post it to the webserver.  Since the values post to the webserver, the people behind the webserver have the ability to view the values.  So, what types of information can be disclosed?  Anything that is contained within your Enviromental variables, for example.

RSnake put up a page that will allow you to try this out:  You will see that the appdata and Computer name should display in the resulting page.

RSnake has asked that if anyone could get this URL to work without requiring a user to type it in their address bar.  Several posters commented that they tried embedding the URL in images, IFrames, etc and couldn't do it.

Pretty interesting stuff. 

