|
|
|
|
|
[
Permlink
| « Hide
]
Till Stirling - 18/Sep/07 03:02 AM
Forgot the source URL: http://www.gnucitizen.org/blog/ie-pwns-secondlife
Wow... either this is a problem with IE's handling of url-handlers such as secondlife://, or it's a problem with second life's argument parsing. Either way, this is a nasty little piece of work.
It's not a good idea to post exploits like this in the public JIRA, although it's kind of a moot point since the author of the exploit posted it on their website. Please use the Report Bug tool in-world and mention this JIRA issue and mark the issue as an Exploit. LL needs to know about this. There's forum talk about this, too.
And It's not just IE.. I've produced a binary patch for this for the windows viewer version 1.18.2.0
I can attach the utility (2kb) if that would be useful to anyone. This zip file contains a 6kb executable file which will patch the windows 1.18.2.0 secondlife viewer executable to remove the loginuri feature and prevent the exploit from working.
A readme file is also included explaining how to utilize the patch. This would appear to be an opening for a "man in the middle" attack,
server acceptance of the XML-RPC with pass-through to the master LL servers for authentication, any "successful" logins can then have the log stored with unsuccessful logins removed from the sesion logging |
||||||||||||||||||||||||||||||||||||||||||||||||||||||