RE: MHTML Redirection Leads to Downloading EXE and Executing

From: James C. Slora, Jr. (james.slora_at_phra.com)
Date: 11/26/03

  • Next message: Bojan Zdrnja: "Remote execution in My_eGallery"
    Date: Tue, 25 Nov 2003 19:24:57 -0500
    To: "Liu Die Yu" <liudieyuinchina@yahoo.com.cn>, <bugtraq@securityfocus.com>
    
    

    Liu Die Yu wrote Tuesday, November 25, 2003 4:51 AM

    > MHTML Redirection Leads to Downloading EXE and Executing
    > http://www.safecenter.net/UMBRELLAWEBV4/MhtRedirLaunchInetExe/MhtRedirLaunchInetExe-Demo.zip

    mhtml:res: also seems to work just fine most of the time. It seems to work even better with MS03-048 applied.

    Without MS03-048:
    --------------------------
    CODEBASE='mhtml:file://C:\NO_SUCH_MHT.MHT!etc
    CODEBASE='mhtml:res://C:\NO_SUCH_MHT.MHT!etc
    within the same file caused both to execute. It also worked if the browser was refreshed to code containing only mhtml:res: if mhtml:file: was opened before the refresh.

    I could not get mhtml:mid: to work though.
    CODEBASE='mhtml:mid://C:\NO_SUCH_MHT.MHT!etc
    added to the same file causes the mhtml:res: to fail even if it precedes the mhtml:mid:. mhtml:file: still works even if mhtml:mid is present too.

    With MS03-048:
    --------------------------
    mhtml:res: works almost all the time (fails just after reboot - mhtml:file: also fails on first IE instance after reboot, even with a refresh)
    mhtml:mid: does not work but does not cause mhtml:res: to fail!

    Win2K Server US English and IE, up to date 2003-11-25 (and tested without 2003-11 updates)


  • Next message: Bojan Zdrnja: "Remote execution in My_eGallery"

    Relevant Pages

    • Re: Add another domain user group to local administrators of all computers in an OU with removing ot
      ... By default, Group Policy refreshes in the background every 90 minutes, with ... I have now waited beyond the refresh time + offset time (it had been ... the group to local administrators at every reboot. ...
      (microsoft.public.windows.server.active_directory)
    • Interjet requires warm reboot from 5.x boot loader?
      ... When warm/cold booting an Interjet under FreeBSD 5.2.1 or 5.3 (vanilla ... I get the same error until I reboot from OK. ... Unfortunately, since cold-booting always fails, this makes the boxes ... Loading /boot/defaults/loader.conf ...
      (freebsd-questions)
    • Re: Configure ftp base dir doesnt work...
      ... Yes, i can change the default directory and don't need a refresh, new settings will be used. ... No, i never reboot the system, because the image is always load from flash with it's default settings set by platform builder. ... I get the platform builder from my colleague at monday to debug the ftp service. ...
      (microsoft.public.windowsce.app.development)
    • Re: Start-up disasters
      ... known good hard drive and see if the reboot failures still occur. ... On the other hand if the repair shop's drive also fails to reboot then ... you have a motherboard problem. ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Computer shout down
      ... XP will reboot when a program crashes or fails by default. ... program is failing ... you can have a look at the Event Viewer in Administrative Tools in the ...
      (microsoft.public.windowsxp.general)