|
Brought to you by:
Suppliers of:
|
|
|
| |
| "Hotfoon is a new type of Internet telephony that is very inexpensive, easy to setup and use. Hotfoon's current service enables you to: Make long distance calls at near local rates. Talk to other Hotfoon users for free." Hotfoon will automatically open URLs sent to the user without user intervention. |
| |
Credit:
The information has been provided by Saudi Linux.
|
| |
An attacker can exploit chat with user by sending a link to random user and Hotfoon directly open the link in IE (or the default web browser) without alerting the user.
Exploit Method:
1) Open Hotfoon program
2) Select chat to random user
3) In chat window ,send the URL that contains bad code such as ( XSS, Internet Explorer exploit or EXE file with a web downloader ..etc )
4) The web browser or Internet Explorer (tested in Internet Explorer) will directly open the link without alert user
|
|
|
|
|