http://encyclopediadramatica.com/Firefox_XPS_IRC_Attack 0day… - Andrew Auernheimer — LiveJournal
0day security advisory alert from the goatse security team
From: (Anonymous) Date: January 28th, 2010 12:34 am (UTC) (link)
hep From: hep Date: January 28th, 2010 01:56 am (UTC) (link)
weev From: weev Date: January 28th, 2010 03:52 pm (UTC) (link)
weev From: weev Date: January 28th, 2010 03:54 pm (UTC) (link)
#1 -- for sure. i've got a PoC on TCP SIP devices, as well as some other fun stuff in the works I don't want to talk about.

#2 -- probably never

#3 -- IE's domain security model simply doesnt allow you to do it. it isn't about blocked ports.
weev From: weev Date: January 28th, 2010 06:07 pm (UTC) (link)
no. it can submit a form to another domain, easy. you just can't shove more shit down the socket that isn't included in the args for the initial POST. and it's all going to be nicely encoded as an HTTP header should be according to the RFC, and not going to be able to be parsed as another protocol very easily.
