RE: [Full-Disclosure] Windows (XP SP2) Remote code execution with parameters

From: Goencz, Otto (OGoencz_at_ghi.com)
Date: 12/28/04

  • Next message: ChrisDay_at_HBOSplc.com: "[Full-Disclosure] A New Year Request"
    To: ShredderSub7 SecExpert <shreddersub7@hotmail.com>, full-disclosure@lists.netsys.com
    Date: Tue, 28 Dec 2004 08:22:21 -0500
    
    
    

    On my box, WinXP with SP2, the PoC worked as described...

    -----Original Message-----
    From: ShredderSub7 SecExpert [mailto:shreddersub7@hotmail.com]
    Sent: Monday, December 27, 2004 7:24 PM
    To: full-disclosure@lists.netsys.com
    Subject: [Full-Disclosure] Windows (XP SP2) Remote code execution with
    parameters

    PoC (called CMDExe): http://www.freewebs.com/shreddersub7/htm.htm
    Discussion: http://www.freewebs.com/shreddersub7/expl-discuss.htm

    ------------------Which systems are vulnerable?--------
    Any system running any Microsoft Windows XP edition with Internet Explorer 6

    or higher, even with SP2 applied.
    Any system running any Microsoft Windows Server 2003 edition with Internet
    Explorer 6 or higher.

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: ChrisDay_at_HBOSplc.com: "[Full-Disclosure] A New Year Request"

    Relevant Pages

    • Re: [Full-disclosure] Windows XP SP2 .manifest file BSOD
      ... [Full-disclosure] Windows XP SP2 .manifest file BSOD ...
      (Full-Disclosure)
    • [Full-disclosure] msgina.dll BSOD
      ... Tested on Windows XP SP2 fully patched. ... Here's the instant PoC: ... Full-Disclosure - We believe in it. ...
      (Full-Disclosure)
    • [Full-Disclosure] "MS Blast" Win2000 Patch Download
      ... It is probably worth mentioning here that the patch for Windows 2000 would require at least SP2, so have that handy... ... Full-Disclosure - We believe in it. ...
      (Full-Disclosure)
    • Re: Windows Startup Taking a Long Time
      ... It may help speed up your system, but it should be clean ... using Windows XP "prettifications". ... As for Service Pack 2 (SP2) for Windows XP, ... You should at least turn on the built in firewall. ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Slow startup and shutdown
      ... > applications that have always been present, ... The problem began before loading SP2 and hasn't changed. ... using Windows XP "prettifications". ... You should at least turn on the built in firewall. ...
      (microsoft.public.windowsxp.perform_maintain)

  • Quantcast