what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Spoofing Technique

Spoofing Technique
Posted Feb 9, 2010
Authored by mc2_s3lector

Whitepaper called spoofing technique.

tags | paper, spoof
SHA-256 | 9cf5bb03c9b206a026568fc09c49e0e27937b42598a05896f187da1388b29970

Spoofing Technique

Change Mirror Download
[+] Category   :  Spoofing     
[+] Category : Spoofing Technique
[+] Author : yogyacarderlink.web.id
[+] Contact : (00x0---www.yogyacarderlink.web.id
[+] date : 4-2-10
[+] biGthank to : Allah SWT,jasakom,KeDai Computerworks,0n3-d4y n3ro,eplaciano, all*.indonesian like a coding,


<frame
src=”http://server/file.html”>)

(http://server/page?frame_src=http://examp
le/file.html)

replace
“frame_src” parameter value with
“frame_src=http://you.example/spoof.html”

user expected domain example.com--->foregion data you.example.com

links can be sent to a user via email,messages, left on bulletin board post,
or forced upon users by Xss attacker. If you gets a user to visit a web
page designated by their malicious address, the user will believe he is
view authentication from address when he is not. Users will
implicitly trust the spoofed since the browser url bar
displays http://example, when in fact the underlying frame htm
is referencing http://you.example

exploits attack the trust relationship established between the
user& the web site. The technique has been used to create fake
web pages including defacements,login acces forms, false press releases,etc

sampling:
Creating a spoofed press release. Lets say a web site use created HTML frames
for their press release web pages.
A user would visit a link such as


(http://example/pr?pg=http://example/pl/03xxx.html). The resulting web page HTML would be:

code:

<HTML>
<FRAMESET COLS=”100, *”>
<FRAME NAME=”pl_menu” SRC=”menu.html”>
<FRAME NAME=”pl_content”
SRC=”http://example/pr/03xxx.html>
</FRAMESET>
</HTML>


“pl” web apps in samplign creates HTML with a static menu&dynamic generated frame src.
“pl_content” frame pulls its source from the URL parameter value
of “pg” to display the requested press release content. But what if an
you(attacker) altered the normal URL to
http://foo.example/pr?pg=http://attacker.example/sp
oofed_press_release.html? Without properly sanity checking
the “pg” value, the resulting HTML would be


Snippet code:
<HTML>
<FRAMESET COLS=”100, *”>
<FRAME NAME=”pl_menu” SRC=”menu.html”>
<FRAME NAME=”pl_content” SRC=”
http://you.example/spoofed_press_release.html”>
</FRAMESET>
</html>

end user you.example.com
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close