Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-28-2003, 02:12 PM   #1
JSA Matt
So Fucking Banned
 
Join Date: Aug 2003
Location: San Diego, CA
Posts: 5,464
Internet Explorer Exploit

I've just seen an exploit that can save and execute an exe file to your computer through an HTML page in internet explorer. The code is written in VBScript and uses a little ASP to hide what it's doing.

Just a heads up people.. be careful.

Has anyone else seen this? I have the code to prove it.

JSA Matt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 02:13 PM   #2
cluck
Confirmed User
 
Join Date: Dec 2002
Location: New Jersey
Posts: 5,248
I discovered another one about a year ago that still works on all versions/settings. I'm keeping that to myself though!
__________________
icq 279990726
www.mcdonalds.com <- great money making opportunity
cluck is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 02:14 PM   #3
SMG
Confirmed User
 
Join Date: Aug 2003
Posts: 1,798
this is why activex is disabled on my ie
__________________
TGP Webmasters: sign up for the top 100 tgp list!
Submit galleries
If you add me to icq (title) make sure to mention GFY or I'll think you're a bot and deny you.
SMG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 02:14 PM   #4
bigdog
Confirmed User
 
Join Date: Jul 2001
Posts: 6,964
this shit is getting scary. Thats why i try to use mozilla a lot
bigdog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 02:17 PM   #5
JSA Matt
So Fucking Banned
 
Join Date: Aug 2003
Location: San Diego, CA
Posts: 5,464
Quote:
Originally posted by SMG
this is why activex is disabled on my ie
I have all ActiveX disabled except the plug-ins (so I can still see flash/j@v@script
JSA Matt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 03:18 PM   #6
JSA Matt
So Fucking Banned
 
Join Date: Aug 2003
Location: San Diego, CA
Posts: 5,464
I guess everyone already knows about this?
JSA Matt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 03:44 PM   #7
extreme
Confirmed User
 
Industry Role:
Join Date: Oct 2002
Location: lalaland
Posts: 2,120
Mmm, its old.

You can test if You're vuln here:

http://www.signupsluts.com/harmless_vuln_test.html

Totally harmless test.
extreme is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 03:47 PM   #8
Trax
[----------------------]
 
Join Date: Aug 2001
Posts: 14,486
Trax is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 04:34 PM   #9
JSA Matt
So Fucking Banned
 
Join Date: Aug 2003
Location: San Diego, CA
Posts: 5,464
Quote:
Originally posted by extreme
Mmm, its old.

You can test if You're vuln here:

http://www.signupsluts.com/harmless_vuln_test.html

Totally harmless test.
How old can it be? I just updated Windows XP when the DCOM worm was going around and now they have a patch for it in Windows Update.

Thanks for the test.. got everything patched
JSA Matt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 04:38 PM   #10
KMR Stitch
I am cool
 
Join Date: Jul 2003
Posts: 14,494
Litte bit of Active-x a tab bit of hahahahahahahahahaha...I dash of .hta in your temp folder..and exe file on a server a little script to read...


TADA!


Ownage. Welcome to mime exploit 9d8
KMR Stitch is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 06:07 PM   #11
extreme
Confirmed User
 
Industry Role:
Join Date: Oct 2002
Location: lalaland
Posts: 2,120
Quote:
Originally posted by JSA Matt


How old can it be? I just updated Windows XP when the DCOM worm was going around and now they have a patch for it in Windows Update.

Thanks for the test.. got everything patched
well, over a week anyhow ;)


--------
Internet Explorer Object Data Remote Execution Vulnerability

Release Date:
August 20, 2003

Reported Date:
May 15, 2003

Severity:
High (Remote Code Execution)

Systems Affected:
Microsoft Internet Explorer 5.01
Microsoft Internet Explorer 5.5
Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 6.0 for Windows Server 2003
--------
extreme is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-28-2003, 09:27 PM   #12
JSA Matt
So Fucking Banned
 
Join Date: Aug 2003
Location: San Diego, CA
Posts: 5,464
Quote:
Originally posted by extreme


well, over a week anyhow ;)
Watch out now
JSA Matt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.