| 
	     You are here  | 
        blog.burntsushi.net | ||
| | | | | 
            
              blog.jle.im
             | 
        |
| | | | | Weblog of Justin Le, covering various adventures in programming and explorations in the worlds of computation physics, and knowledge. | |
| | | | | 
            
              boyter.org
             | 
        |
| | | | | ||
| | | | | 
            
              p1k3.com
             | 
        |
| | | | | ||
| | | | | 
            
              badoption.eu
             | 
        |
| | | ZipJar, a little bit unexpected attack chain The upcoming from the .zip TLDs from Google brought some discussion about attack vectors. Most of those attack vectors are not completely new, like using an "@" to split between username and host. While playing a little bit around, an unexpected attack chain appeared, involving a .zip TLD, Windows Explorer, WebDAV and a jar file. Some further reading and research: https://www.kaspersky.com/blog/zip-mov-domain-extension-confusion/48254/ https://www.mandiant.com/resources/blog/url-obfuscation-schema-abuse https://mrd0x.com/file-archiver-in-the-browser/ | ||