[Full-Disclosure] another Trojan with the ADO hole? + a twist in the story

From: Gadi Evron (ge_at_egotistical.reprehensible.net)
Date: 01/31/04

  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] MyDoom download info"
    To: bugtraq@securityfocus.com
    Date: Sat, 31 Jan 2004 19:35:06 +0200
    
    

    The past Trojan horses which spread this way took advantage of the fact
    web servers send an HTML 404 message if a file doesn't exist.

    The original sample - britney.jpg - was simply an html file itself, and
    using that fact, and IE loading it. It was combined with one of the
    latest exploits of the time (I don't think MS patched it yet), and
    downloaded the Trojan horses.

    This time around there is actually a picture on the web page, of a real
    honest to God girl. But in another frame.. the same story all over again.

    For blocking purposes, the (un-safe) URL is: http://ut.uk.to/cs.jpg .

         Gadi Evron.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Valdis.Kletnieks_at_vt.edu: "Re: [Full-Disclosure] MyDoom download info"

    Relevant Pages

    • another Trojan with the ADO hole? + a twist in the story
      ... The past Trojan horses which spread this way took advantage of the fact ... web servers send an HTML 404 message if a file doesn't exist. ... The original sample - britney.jpg - was simply an html file itself, ...
      (Full-Disclosure)
    • another Trojan with the ADO hole? + a twist in the story
      ... The past Trojan horses which spread this way took advantage of the fact ... web servers send an HTML 404 message if a file doesn't exist. ... The original sample - britney.jpg - was simply an html file itself, ...
      (Bugtraq)
    • Re: Spyware, Viruses via HTML in Email
      ... HTML script embedded in HTML can do just about anything. ... 97.5% of 14,288 Trojan horses used in the test, according to PC World. ... Trojan horses can carry worms or viruses. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: HP VMS web site: terrible coding of background colour
      ... Go back to the roots of HTML. ... Another one is developpers who are clueless on web servers and do not make use ... (They could at least just use the standard HTML way with the <META tag). ... server automatically embeds another file into the file being served. ...
      (comp.os.vms)
    • Re: Plain text files in internet explorer
      ... >text/plain to allow the student to read the markup, ... >the hard disk as .html. ... Look how elegantly web servers handle that *specific* ... Photoshop makes a JPEG. ...
      (Vuln-Dev)