Re: AIM-based worm?

From: skipperat_private
Date: Sat Sep 28 2002 - 04:10:34 PDT

  • Next message: Jason Robertson: "RE: E-Card Remote Code Execution Scam"

    Hi,
    
    > I dunno about the buddy list thing, but the inability to view the source in
    > IE isn't surprising.  Note that the HTML below contains a META refresh that
    > redirects you to the .com file.  Once this fires, the browser discards the
    > HTML file containing the redirect and reqeusts the .com file.  When you
    > cancel the download dialog and try to view source, there's nothing to see
    > because the browser has no document loaded.  If you turn off Meta refresh
    > before hitting the page, you'd see the HTML page below, and could view the
    > source.
    
    A good reflex would be to telnet the web server and to type this:
    GET / HTTP/1.0
    [then hit enter 2 times]
    
    It will allow you to see what you want, without being annoyed by your browser 
    !
    
    Cya
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Sat Sep 28 2002 - 17:46:15 PDT