MSIE->LinkillerJPU:another caller-based authorization(is broken).

From: Liu Die Yu (liudieyuinchina_at_yahoo.com.cn)
Date: 09/10/03

  • Next message: Guy Barnum: "Microsoft security update broken?"
    Date: 10 Sep 2003 05:32:10 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    LinkillerJPU:another caller-based authorization(is broken).

    [tested]
    Browser Ver
    {
    MS Internet Explorer: 6.0.2600.0000.xpclnt_qfe.021108-2107;
    Encryption: 128-bit;
    Patch:; Q810847;
    }
    (So, it's far from fully patched.)
    OS Ver: "Windows XP Cn ver"

    [demo]
    http://www.safecenter.net/liudieyu/LinkillerJPU/LinkillerJPU-MyPage.HTM
    or
    http://umbrella.mx.tc
    ---> LinkillerJPU section
    ---> LinkillerJPU-MyPage file

    [exp]
    refer to "Linkiller" at UMBRELLA.MX.TC
    progress: i found caller-based authorization is also
    used when
    [WindowObj].location.href="javascript:[JpuScript]"

    [how]
    when i have a hammer, i search for a nail.

    [greetings]
    the Pull, dror, guninski, http-equiv, sandblad,
    greymagic and "Friedrich L.Bauer"(man, for your
    execellent book).
    of course, mom and dad.

    best wishes

    -----
    from http://Umbrella.MX.TC on http://SafeCenter.NET


  • Next message: Guy Barnum: "Microsoft security update broken?"

    Relevant Pages

    • MSIE->LinkillerSaveRef:another caller-based authorization
      ... Browser Ver ... MS Internet Explorer: 6.0.2600.0000.xpclnt_qfe.021108-2107; ... ---> LinkillerJPU section ... "method caching attack" still works if root-caller is ...
      (Bugtraq)
    • MSIE->BackMyParent2:Multi-Thread version
      ... Browser Ver ... Encryption: 128-bit; ... OS Ver: "Windows XP Cn ver" ... ---> BackMyParent2 section ...
      (Bugtraq)
    • Re: Mitsubishi DV648UT scanner
      ... my system one in Windows and one in winnt. ... Ver 1.8.1.3 in both folders and also the downloaded Ver 1.8.1.2, ... my Google results are located at: ...
      (microsoft.public.windowsxp.hardware)
    • Re: Windows 2003 : Cannot display network connections
      ... Download and install Ver. ... Windows Server 2003/2000/NT; CCA ... The service "Network connections" is not started, ... Internet explorer cannot connect to the internet any more. ...
      (microsoft.public.windows.server.networking)
    • Re: not a signed file
      ... C:\WINDOWS\$NtUninstallKB896688-IE6SP1-20051004.130236$\DANIM.DLL ver ... KB905915-IE6SP1-2005Microsoft Windows Component Publisher ... Microsoft Security Bulletin MS05-054 ...
      (microsoft.public.windowsxp.general)