Apropos little: UNC path filtering is something the Rails generation of webdevs have a bad habit over overlooking.
Apropos little: UNC path filtering is something the Rails generation of webdevs have a bad habit over overlooking.
If it's a targeted attack I suppose you have a better shot, are most home windows user names set to the user's full name like "John Doe"?
But if you made some sort of Javascript "game" (which used drag and drop) and required the users to register their name first, then you should have a fairly high chance of guessing their username without CIFS.
It's clever! I don't want to take anything away from it, except that I think it's been written up somewhat breathlessly.
Grossman probably has a good point that most applications aren't even superficially protected against clickjacking, and so this isn't going to be a common attack any time soon.