Self-Executing FOLDERS: Windows XP Explorer Part V

http-equiv_at_excite.com
Date: 01/25/04

  • Next message: Joe Dance: "Windows Update Error 0x800C0008 after updating the WU client"
    Date:         Sun, 25 Jan 2004 16:51:00 -0000
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Sunday, January 25, 2004

    The following file is a 'folder' comprising both scripting and
    an executable [*.exe].

    We inject scripting and an executable into the 'folder' which is
    designed to point back to the executable in the 'folder' and
    execute it. Provided the 'folder' is an html file, Windows XP
    Explorer will execute it.

    Because it is an 'folder' proper, Windows Explorer opens it. The
    scripting inside is then parsed and fired. That scripting is
    pointing back to the same executable file and because it is a
    self-executing 'folder', it executes !

    Fully self-contained harmless *.exe.

    Windows XP only:

    http://www.malware.com/my.pics.zip

    Be aware of 'folders' out there.

    --
    http://www.malware.com
    -----
    Editor's Note: The 43rd Most Powerful Person in Networking says...
    Out of Office replies to list messages cause you to be unsubscribed automatically. Either subscribe a Public Folder, or ensure your rules are set to ensure list messages are filtered prior to your Out of Office reply. Such automatic replies are a bane to posters, and cause us to have fewer researchers post to NTBugtraq.
    -----
    

  • Next message: Joe Dance: "Windows Update Error 0x800C0008 after updating the WU client"

    Relevant Pages

    • RE: Self-Executing FOLDERS: Windows XP Explorer Part V
      ... Pics.html" to "My Pics.Folder", it's still an HTML file and not a folder. ... promised to do in Service Pack 2 for Windows XP. ... Windows XP Explorer will execute it. ...
      (Bugtraq)
    • Re: Cannot install update814033
      ... renaming or deleting the Catroot2 folder may ... >Check your windows update.log file for specific error ... >Microsoft MVP Scripting and WMI, ... Can not delete or rename the folder catroot2... ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Cannot Access User Files
      ... > documents and setting folder private.. ... Take Ownership of a File or Folder in Windows XP ... Microsoft MVP Scripting and WMI, ...
      (microsoft.public.windowsxp.security_admin)
    • Re: 0x8024001D
      ... I am actually running a german Windows ... >> Delete the SoftwareDistribution folder and see if it helps. ... >> folder is that you lose your WU/AU History listing. ... >> torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway ...
      (microsoft.public.windowsupdate)
    • Re: Not able to access user files
      ... Shreyank wrote: ... > i just reinstalled my windows xp sp1....the problem is that in my older ... "Access is Denied" Error Message When You Try to Open a Folder ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
      (microsoft.public.windowsxp.security_admin)

  • Quantcast