Internet Explorer 6 - File Stealing


Stealing files from Internet Explorer 6 users is extremely easy if the user can be induced into typing a sufficient amount of text. Any well-known file could be targeted and automatically upload once the proper characters are captured.


The following series of blog posts explore these demonstrations in detail:


These demonstrations are based ideas presented by Charles McAuley in June of 2006: file upload widgets in IE and Firefox have issues and Bart van Arnhem: Re: file upload widgets in IE and Firefox have issues. By combining the two concepts, stealing files is nearly trivial.