elhacker.net cabecera Bienvenido(a), Visitante. Por favor Ingresar o Registrarse
¿Perdiste tu email de activación?.
 
Inicio Ayuda Buscar Ingresar Registrarse
25 Mayo 2012, 19:17  


Tema destacado: Grupo de Facebook de elhacker.net

+  Foro de elhacker.net
|-+  Seguridad Informática
| |-+  Bugs y Exploits (Moderador: berz3k)
| | |-+  (More Exploit Code is Available) Microsoft IE AnchorClick Behavior and HTML Help
0 Usuarios y 1 Visitante están viendo este tema.
Páginas: [1] Ir Abajo Respuesta Imprimir
Autor Tema: (More Exploit Code is Available) Microsoft IE AnchorClick Behavior and HTML Help  (Leído 580 veces)
Man-In-the-Middle
Colaborador
***
Desconectado Desconectado

Mensajes: 3.645



Ver Perfil
(More Exploit Code is Available) Microsoft IE AnchorClick Behavior and HTML Help
« en: 30 Noviembre 2004, 07:02 »

[Tested]
IEXPLORE.EXE file version 6.0.2900.2180
MSHTML.DLL file version 6.00.2800.1400
Microsoft Windows XP Home SP2

[Discussion]
Recently, a security professional aliased http-equiv (malware.com) found a vulnerability in Microsoft's new Service Pack (SP2). What
 was required to compromise the victim's machine was the dragging of an specially-crafted into a folderview window, and then the clicking
 of a button. LongNameVuln is a more efficient way of acheiving this common goal of compromising the system. It removes the extra
 step of having to click a button in order to access a page on the local machine. It can be done easily. Using the Related Topics
 command of Microsoft's Help ActiveX Control, any page can be loaded into a target frame. Unfortuneatly, only addresses that actually
 point to a location can be used. This does not include protocols such as javascript and vbscript. However, we can still break out
 of the Internet Zone and open up a page in the local zone. That is what this vulnerability achieves.

The example shows the picture of a garden which includes a carrot. Dragging the carrot to the bottom frame in the browser (set up
 to be the outside of the garden) will copy a file to PCHealth directory in C:\windows, which will then be launched, creating another
 file in the same directory called Greyhats.hta, which must be launched manually. The directory could easily be changed to shell:startup,
 however this is not necissary for this example. This is the same payload as given in NoCeegar on malware.com because my server doesn't
 have the capabilities to host the payload file like malware.com does :).

View the example at http://freehost07.websamba.com/greyhats/longnamevuln.htm
En línea
tinker77

Desconectado Desconectado

Mensajes: 2


Ver Perfil
Re: (More Exploit Code is Available) Microsoft IE AnchorClick Behavior and HTML
« Respuesta #1 en: 1 Diciembre 2004, 08:07 »

Man-In-the-Middle,  tu puedes hacerlo funcionar?  Mi winxp no permite que  se abra la pagina html con el codigo final.   =(
En línea
Páginas: [1] Ir Arriba Respuesta Imprimir 

Ir a:  

Mensajes similares
Asunto Iniciado por Respuestas Vistas Último mensaje
Separar partes de un un html code
Programación Visual Basic
extreme69 8 843 Último mensaje 22 Febrero 2011, 16:51
por ignorantev1.1
Un exploit creado por Microsoft es publicado en foros chinos
Noticias
wolfbcn 0 282 Último mensaje 8 Mayo 2012, 13:02
por wolfbcn
Powered by SMF 1.1.16 | SMF © 2006-2008, Simple Machines