OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype

From: KJK::Hyperion (hackbunnys0ftpj.org)
Date: Sun Oct 07 2007 - 17:49:01 CDT


Paul Szabo ha scritto:
> Windows already does special %-decoding to URL protocol handlers as per
> http://msdn2.microsoft.com/en-us/library/aa767914.aspx
> (whereas I do not think it does that to most other application launch
> registry keys). It should also protect blanks and quote characters, and
> anything else that could upset or confuse later processing.

I will look into the matter. Now I'm curious where, exactly, the shit
happens. We're bound to learn something from the experience

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/