[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] iFriends free video chat exploit



On Fri, 28 Dec 2007 16:09:23 CST, Ifriends Exploit said:

> If you don't have an iFriends account, and do not wish to get one, find a
> chathost utilizing EasyCam, and enter their Guest Chatroom, follow the steps
> above, except look for a file named "LSChatViewG.swf" instead... this is the
> flash file for guest chats. Once you've downloaded this file, you'll need to
> use a Flash decompiler to decompile this file, and then delete the privacy
> screen and recompile it.

Gaak. ;)

Remember kiddies - friends don't let friends deploy systems that depend on
untrusted end hosts to do validation of critical information for them.. .;)

Attachment: pgpX7vuTkrqP0.pgp
Description: PGP signature

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/