|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Alexander Sotirov (asotirov
determina.com)
Date: Tue Apr 03 2007 - 21:53:42 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Larry Seltzer wrote:
>>> Larry, why are you so curious about how this exploit works?
>
> Because the Firefox docs say they don't support ANI files for cursors
> and I can't get any non-malicious ones to work in it. I have to admit
> I'm having trouble getting them to work in IE now too.
That's correct, Firefox doesn't support ANI files for cursors. If the
exploitation method was so obvious, we would already have Firefox exploits in
the wild, wouldn't we?
> What's wrong with this code?
>
> <HTML>
> <BODY>
> <style type="text/css">
> BODY{cursor: url(http://www.larryseltzer.com/DRUM.ANI);}
> </style>
Maybe the url should be in quites? This works for me:
<body style="CURSOR: url('foo.ani')">
Alex
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]