Hello, "I can also confirm that this attack works on iPhone, iPad and Mac's default mail client."
Of course, it works anywhere where arbitrary client-side code can be executed... IMAHO, the issue here is not your iphone loading images, there are millions of attack vectors to trigger this attack... The problem is the CSRF weaknesses of your router admin panel that should be fixed by synchronizing a secret token or by using any other well known mitigation strategy against these attacks. Best Regards, Guifre. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
