MSIE->HijackClick: 1+1=2

From: Liu Die Yu (liudieyuinchina_at_yahoo.com.cn)
Date: 09/10/03

  • Next message: hUNTER 007: "Multiple* bug's associated with Win xp default zip Manager..."
    Date: 10 Sep 2003 05:19:33 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    HijackClick: 1+1=2.

    [tested]
    Browser Ver
    {
    MS Internet Explorer: 6.0.2600.0000.xpclnt_qfe.021108-2107;
    Encryption: 128-bit;
    Patch:; Q810847;
    }
    (So, it's far from fully patched.)
    OS Ver: "Windows XP Cn ver"

    [demo]
    (POF VER)
    http://www.safecenter.net/liudieyu/HijackClick/HijackClick-MyPage.HTM
    or
    http://umbrella.mx.tc
    ---> HijackClick section
    ---> HijackClick-MyPage file

    (ATTACK VER)
    http://www.safecenter.net/liudieyu/HijackClick/HijackClick2-MyPage.HTM
    or
    http://umbrella.mx.tc
    ---> HijackClick section
    ---> HijackClick2-MyPage file

    [exp]
    dragNdrop!
    for image, it copies file.
    for link, it creates shortcut.

    but, some guy is lazy.
    he moves the window instead of the mouse.
    then a click event(mousedown&mouseup) becomes
    mousedown&mousemove&mouseup == dragNdrop.

    then "POF VER" in the "[demo]" section shows a click
    indeed can be transformed into a dragNdrop.
    then "ATTACK VER" in the "[demo]" section drags my
    homepage to your favorite list.

    [how]
    special thanks to:
    the lazy guy mentioned in the "[exp]" section:
    his handle is "jelmer";
    and his great invention "internet explorer local file
    reading";
    and myself :-)
    for some trivial work.

    [greetings]
    the Pull, dror, guninski, http-equiv, jelmer and
    "Friedrich L.Bauer".
    of course, mom and dad.

    best wishes

    -----
    from http://Umbrella.MX.TC on http://SafeCenter.NET


  • Next message: hUNTER 007: "Multiple* bug's associated with Win xp default zip Manager..."

    Relevant Pages

    • Re: Windows 2003 : Cannot display network connections
      ... Download and install Ver. ... Windows Server 2003/2000/NT; CCA ... The service "Network connections" is not started, ... Internet explorer cannot connect to the internet any more. ...
      (microsoft.public.windows.server.networking)
    • Re: Is it true IE 7 does not work with Windows XP?
      ... uninstall Internet Explorer Ver. ... And can I install IE Ver. ... DSL services you have), with Windows XP, SP3 on ... MS Internet Explorer 7 works fine. ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Mitsubishi DV648UT scanner
      ... my system one in Windows and one in winnt. ... Ver 1.8.1.3 in both folders and also the downloaded Ver 1.8.1.2, ... my Google results are located at: ...
      (microsoft.public.windowsxp.hardware)
    • Re: not a signed file
      ... C:\WINDOWS\$NtUninstallKB896688-IE6SP1-20051004.130236$\DANIM.DLL ver ... KB905915-IE6SP1-2005Microsoft Windows Component Publisher ... Microsoft Security Bulletin MS05-054 ...
      (microsoft.public.windowsxp.general)
    • Re: Three C questions
      ... I am using Borland's Turbo C ver 3.0 for MS DOS. ... With Borland product, I can not find a BGI driver for this mode. ... port it later to windows xp anyway... ...
      (comp.lang.c)

    Loading