Re: Rather large MSIE-hole

From: jon schatz (jon@divisionbyzero.com)
Date: 03/14/02


From: jon schatz <jon@divisionbyzero.com>
To: KF <dotslash@snosoft.com>
Date: 14 Mar 2002 14:50:00 -0800


On Thu, 2002-03-14 at 13:56, KF wrote:
> Sorry if someone else has said this... but has anyone tryed using + as a
> space like you had to when using cmd.exe via unicode exploit?

i tried that a week ago like so:

var programName=new Array(
        'c:/winnt/system32/cmd.exe+/c+c:/winnt/system32/calc.exe'
);

no dice on Win2k+sp2+ie6

-jon

-- 
jon@divisionbyzero.com || www.divisionbyzero.com
gpg key: www.divisionbyzero.com/pubkey.asc
think i have a virus?: www.divisionbyzero.com/pgp.html
"You are in a twisty little maze of Sendmail rules, all confusing." 




Relevant Pages

  • Re: combinations of 4
    ... "You are in a twisty little maze of Sendmail rules, all confusing." ...
    (Vuln-Dev)
  • Re: modifying SUID
    ... > However, this command works sometimes, and sometimes only results in ... "You are in a twisty little maze of Sendmail rules, ...
    (Security-Basics)
  • Re: IP Protocol #s
    ... On Mon, 2002-05-20 at 10:51, Chisholm Wildermuth wrote: ... "You are in a twisty little maze of Sendmail rules, all confusing." ...
    (Security-Basics)
  • Re: In which we exercise the UPS yet again
    ... would boot unless 2 of the others were up. ... You are trapped in a maze of twisty little NFS-maps, ... David Cameron Staples | staples AT csse DOT unimelb DOT edu DOT au ...
    (alt.sysadmin.recovery)
  • Re: Thou shalt have no other gods before the ANSI C standard
    ... > You are in a maze of twisty little passages, ... > You are in a maze of twisting little passages, ...
    (sci.crypt)