Exploiting cross-domain scripting vulnerabilities?

From: Alla Bezroutchko (alla@scanit.be)
Date: 08/22/02


Date: Thu, 22 Aug 2002 13:54:44 +0200
From: Alla Bezroutchko <alla@scanit.be>
To: vuln-dev@securityfocus.com

Hello all,

Quite a few browser vulnerabilities (BugTraq ID 5473 - Web Folders HTML
injection - being the latest) allow a web site to execute HTML code in
"Local Computer" security zone. At least those bugs allow a web site to
read local files. My question is: is there anythign else you can do with
this type of bug? Like running arbitrary commands?

Usually you have a piece of text of limited size that you can inject.
This rules out Java applets as far as I understand. Wscript.Shell
ActiveX control also seems to be a problem because IE shows a dialog box
saying something about unsafe ActiveX controls. So is there anything
else interesting one can do with cross-domain scripting?

Alla.



Relevant Pages

  • Re: Windows XP and Media Ctr Compriosn
    ... Windows: XP Home, XP Pro, and Media Ctr. ... On *my* web site? ... bugs fixed. ... Three comments regarding Vista: ...
    (microsoft.public.windowsxp.general)
  • Re: Thank you.
    ... a local computer shop. ... is it your considered view that the web site I ... It's not the fact that's it's a .bat file that makes it good or bad ... A .bat is simply a series of commands. ...
    (microsoft.public.windowsxp.basics)
  • Re: security settings prevent pics loading
    ... The image is *not* in your web site. ... It is referencing your local computer. ... You haven't said what web design program you are using, ...
    (microsoft.public.windowsxp.security_admin)
  • How to save web site properly ?
    ... I have one web site to move to another web hosting server. ... to save the web site to my local computer. ... The saving option use ... I have an account in tripod.lycos.com and lycos allows user to upload ...
    (microsoft.public.frontpage.client)
  • Re: 100% CPU load : how to investigate?
    ... Someone I know is running some Web 2.0-type web site that lives on a ... and is experiencing 100% CPU load after a few hours. ... application and reveal bugs that could explain this CPU load? ... A very well known one is the DBG debugger. ...
    (comp.lang.php)