Vuln in IE6&7 and Firefox reads boot.ini

http://lcamtuf.coredump.cx/focusbug/description.txt

This is a little crazy. using a bug that is in firefox and ie6&7 it records letters that you type and rearages them to load display yer boot.ini and could easy record it in anysense… proof of concept

http://lcamtuf.coredump.cx/focusbug/ffversion.html
Manually type the following text:

C:\ is my boot drive. Incidentally, I like cheese.

http://lcamtuf.coredump.cx/focusbug/ieversion.html
Manually type the following text:

I will never find a date. Thanks to computers and books :\


passage from concept page
“Naturally, this is just a naive example. The same code could be used to divert keystrokes from** web-based
games, weblog entry / comment forms, on-line chats, captchas,** etc. As such, this is be somewhat scary”