[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] The email that hacks you
- To: Bogdan Calin <bogdan@xxxxxxxxxxxx>
- Subject: Re: [Full-disclosure] The email that hacks you
- From: Guifre <guifre.ruiz@xxxxxxxxx>
- Date: Wed, 28 Nov 2012 12:00:09 +0100
Hello,
"I can also confirm that this attack works on iPhone, iPad and Mac's
default mail client."
Of course, it works anywhere where arbitrary client-side code can be
executed... IMAHO, the issue here is not your iphone loading images,
there are millions of attack vectors to trigger this attack... The
problem is the CSRF weaknesses of your router admin panel that should
be fixed by synchronizing a secret token or by using any other well
known mitigation strategy against these attacks.
Best Regards,
Guifre.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/