Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 11-29-2004, 04:33 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,574
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Thumbs down

From: Paul <paul(at)greyhats.cjb.net>

Greyhats Security Group is back and we're ready to kick the crap out of sp2 [img]style_emoticons/<#EMO_DIR#>/smile.gif[/img]. Looks like all the vulnerabilities previously posted by us have been patched. Good work, Microsoft. We're not through yet, though. Here's proof that no matter how many millions of dollors you spend on security, there will always be things you missed. Btw, I codenamed this LongNameVuln because its a lot easier to remember then Help ActiveX Control Related Topics Local Content Accessing Vulnerability [img]style_emoticons/<#EMO_DIR#>/smile.gif[/img]

[Tested]
IEXPLORE.EXE file version 6.0.2900.2180
MSHTML.DLL file version 6.00.2800.1400
Microsoft Windows XP Home SP2

[Discussion]
Recently, a security professional aliased http-equiv (malware.com) found a vulnerability in Microsoft's new Service Pack (SP2). What was required to compromise the victim's machine was the dragging of an specially-crafted into a folderview window, and then the clicking of a button. LongNameVuln is a more efficient way of acheiving this common goal of compromising the system. It removes the extra step of having to click a button in order to access a page on the local machine. It can be done easily. Using the Related Topics command of Microsoft's Help ActiveX Control, any page can be loaded into a target frame. Unfortuneatly, only addresses that actually point to a location can be used. This does not include protocols such as javascript and vbscript. However, we can still break out of the Internet Zone and open up a page in the local zone. That is what this vulnerability achieves.

The example shows the picture of a garden which includes a carrot. Dragging the carrot to the bottom frame in the browser (set up to be the outside of the garden) will copy a file to PCHealth directory in C:\windows, which will then be launched, creating another file in the same directory called Greyhats.hta, which must be launched manually. The directory could easily be changed to shell:startup, however this is not necissary for this example. This is the same payload as given in NoCeegar on malware.com because my server doesn't have the capabilities to host the payload file like malware.com does [img]style_emoticons/<#EMO_DIR#>/smile.gif[/img].
Reply With Quote
Posted


Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
hijack log der Spyware / Virus Removal 46 10-04-2005 06:49 AM
Trojandownloader And Unremovable Files- Woes Me ibrbrt Spyware / Virus Removal 9 06-18-2005 11:28 AM
eliteuvf32.exe?? AdWare? Alex Spyware / Virus Removal 31 05-17-2005 08:50 PM
Windows Media Player ActiveX Control Two Vulnerabi Mobo Security Alerts and vulnerabilities 0 12-20-2004 07:30 PM
Microsoft December security update Mobo News & Announcements 0 12-18-2004 07:30 AM



All times are GMT -5. The time now is 01:19 PM.


Firefox 2