Full Disclosure mailing list archives

Re: morning_wood should stop posting xss


From: madsaxon <madsaxon () direcway com>
Date: Fri, 25 Jul 2003 12:13:46 -0500

At 12:21 PM 7/25/03 -0400, Jason wrote:

tokens for account info in an extranet application, easily catches sql injection, brute force attacks, intellectual property theft...

It's pretty common to use basically the same principle to track
junk mail address lists; i.e., use a variant of your name when
you register for some service and then see what sort of mail
(either postal or electronic) shows up with that telltale
address.

m5x

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: