MSIE7 focus bug demonstration (for Windows)
  • This demonstrates a newly discovered vulnerability in MSIE7, by Michal Zalewski
  • For Firefox version of this attack, click here.
  • For a clarification on BUGTRAQ / Full-Disclosure mess, see this summary.

    Compose your message here:

    Manually type the following text: "I will never find a date. Thanks to computers and books :\"
    This should take you to a page showing a copy of your C:\BOOT.INI file.

    Naturally, this is just a naive example. The same code could be used to divert keystrokes from web-based
    games, weblog entry / comment forms, on-line chats, captchas, etc. As such, this is be somewhat scary.

    Preview of diverted keystrokes (demo only):