GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Internet Explorer Exploit (https://gfy.com/showthread.php?t=168920)

JSA Matt 08-28-2003 02:12 PM

Internet Explorer Exploit
 
I've just seen an exploit that can save and execute an exe file to your computer through an HTML page in internet explorer. The code is written in VBScript and uses a little ASP to hide what it's doing.

Just a heads up people.. be careful.

Has anyone else seen this? I have the code to prove it.

:helpme

cluck 08-28-2003 02:13 PM

I discovered another one about a year ago that still works on all versions/settings. I'm keeping that to myself though!

SMG 08-28-2003 02:14 PM

this is why activex is disabled on my ie :)

bigdog 08-28-2003 02:14 PM

this shit is getting scary. Thats why i try to use mozilla a lot

JSA Matt 08-28-2003 02:17 PM

Quote:

Originally posted by SMG
this is why activex is disabled on my ie :)
I have all ActiveX disabled except the plug-ins (so I can still see flash/j@v@script

JSA Matt 08-28-2003 03:18 PM

I guess everyone already knows about this? :warning

extreme 08-28-2003 03:44 PM

Mmm, its old.

You can test if You're vuln here:

http://www.signupsluts.com/harmless_vuln_test.html

Totally harmless test.

Trax 08-28-2003 03:47 PM

:sleep

JSA Matt 08-28-2003 04:34 PM

Quote:

Originally posted by extreme
Mmm, its old.

You can test if You're vuln here:

http://www.signupsluts.com/harmless_vuln_test.html

Totally harmless test.

How old can it be? I just updated Windows XP when the DCOM worm was going around and now they have a patch for it in Windows Update.

Thanks for the test.. got everything patched :thumbsup

KMR Stitch 08-28-2003 04:38 PM

Litte bit of Active-x a tab bit of hahahahahahahahahaha...I dash of .hta in your temp folder..and exe file on a server a little script to read...


TADA!


Ownage. Welcome to mime exploit 9d8

extreme 08-28-2003 06:07 PM

Quote:

Originally posted by JSA Matt


How old can it be? I just updated Windows XP when the DCOM worm was going around and now they have a patch for it in Windows Update.

Thanks for the test.. got everything patched :thumbsup

well, over a week anyhow ;)


--------
Internet Explorer Object Data Remote Execution Vulnerability

Release Date:
August 20, 2003

Reported Date:
May 15, 2003

Severity:
High (Remote Code Execution)

Systems Affected:
Microsoft Internet Explorer 5.01
Microsoft Internet Explorer 5.5
Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 6.0 for Windows Server 2003
--------

JSA Matt 08-28-2003 09:27 PM

Quote:

Originally posted by extreme


well, over a week anyhow ;)

Watch out now :thumbsup


All times are GMT -7. The time now is 10:41 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123