FFFjacking

0
40

Posted by .cCuMiNn. on Jun 02

Same web browsers allow to show directory index or content of text-based
file in frame, when it is loaded via FILE protokol. It enables hijacking of
informations from user's local disk by drag&drop methods. I call this
technique "FFFjacking (File From Frame hiJacking)". Combination of Windows
XP and Internet Explorer(6,7,8) allows files downloading or uploading
between user's local disk and shared folder on attacker's…

Source: FFFjacking