Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: [Full-Disclosure] YEY AGAIN Automatic remotecompromiseofInternetExplorer Service Pack 2 XP SP2 |
|---|---|
| Date: | Mon, 27 Dec 2004 17:59:03 -0500 |
Had a mistake in my code o well. Works now PoC: http://www.michaelevanchik.com/security/microsoft/ie/xss/index.html http://www.michaelevanchik.com/security/microsoft/ie/xss/writehta.txt <-- avp's should add this Here is some new adodb code AVP's should add. No longer needed to connect to external source. Malicious recordset can be built locally. www.michaelevanchik.com -----Original Message----- From: Michael Evanchik [mailto:mevanchik@relationship1.com] Sent: Monday, December 27, 2004 11:57 AM To: Ron Jackson; full-disclosure@lists.netsys.com Subject: RE: [Full-Disclosure] YEY AGAIN Automatic remotecompromiseofInternetExplorer Service Pack 2 XP SP2 works on around 30 people i know so far. Some it doesnt, You have to be admin, also view the source code you have to have the local html file in c:\windows\pchealth\helpctr\ ect specified Another could have been used -----Original Message----- From: full-disclosure-bounces@lists.netsys.com [mailto:full-disclosure-bounces@lists.netsys.com]On Behalf Of Ron Jackson Sent: Sunday, December 26, 2004 11:14 AM To: full-disclosure@lists.netsys.com Subject: RE: [Full-Disclosure] YEY AGAIN Automatic remotecompromiseofInternetExplorer Service Pack 2 XP SP2 Hmm, Popped up a help window with a few lines of text in it.but that was it. No files in startup. Winxpsp2 fully patched, Sygate personal firewall, Adaware SE professional. ---------------------------------------------------------------------------- From: full-disclosure-bounces@lists.netsys.com [mailto:full-disclosure-bounces@lists.netsys.com] On Behalf Of Michael Evanchik Sent: Sunday, December 26, 2004 12:07 AM To: Aviv Raff; full-disclosure@lists.netsys.com Subject: RE: [Full-Disclosure] YEY AGAIN Automatic remote compromiseofInternetExplorer Service Pack 2 XP SP2 try www.michaelevanchik.com/security/microsoft/ie/xss/index.html might be a little more reliable PoC 1) new not known by AVP codes 2) uses all start up menue languages -----Original Message----- From: Michael Evanchik [mailto:mevanchik@relationship1.com] Sent: Saturday, December 25, 2004 9:11 PM To: Aviv Raff; full-disclosure@lists.netsys.com Subject: RE: [Full-Disclosure] YEY AGAIN Automatic remote compromise ofInternetExplorer Service Pack 2 XP SP2 Hi Aviv, Not sure what your issue is. This has been tested on many people, and it works on everyone. Maybe its your pop up blocker? Maybe its your AVP? This exploit is on Securityfocus and k-otik as they tested as well. Http equiv verified before any post was made to FD. In either case we did not code around pop up blockers nor around known virus strings. This PoC is not for blackhats kiddies. Mike www.michaelevanchik.com -----Original Message----- From: full-disclosure-bounces@lists.netsys.com [mailto:full-disclosure-bounces@lists.netsys.com]On Behalf Of Aviv Raff Sent: Saturday, December 25, 2004 7:47 AM To: full-disclosure@lists.netsys.com; 'Michael Evanchik' Subject: RE: [Full-Disclosure] YEY AGAIN Automatic remote compromise ofInternetExplorer Service Pack 2 XP SP2 Hi, Somehow the POC does not work on both of my WinXPSP2 pro boxes. Both are fully patched, but one is hardened and the other is after a clean install. After running the POC, the IE opens the Help window, but then freezes for a couple of minutes. After IE stops freezing, there is no Microsoft Office.hta on the startup folder. And yes, I'm running this on an Administrator account. Can anyone else confirm this? -- Aviv Raff >From "Zen and the Art of Why Linux Sucks": "Ahh.. Can you smell the 'open source' zealots in the morning?". ------------------------------------------------------------------------ From: full-disclosure-bounces@lists.netsys.com [mailto:full-disclosure-bounces@lists.netsys.com] On Behalf Of Michael Evanchik Sent: Friday, December 24, 2004 6:11 PM To: full-disclosure@lists.netsys.com; bugtraq@securityfocus.com; NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM; vuln@vulnwatch.org Subject: [Full-Disclosure] YEY AGAIN Automatic remote compromise of InternetExplorer Service Pack 2 XP SP2 http://freehost07.websamba.com/greyhats/sp2rc-analysis.htm Microsoft Internet Explorer XP SP2 Fully Automated Remote Compromise Dec, 21 2004 Vulnerable ---------- - Microsoft Internet Explorer 6.0 - Microsoft Windows XP Pro SP2 - Microsoft Windows XP Home SP2 Not Tested ------------------------ - Microsoft Windows 98 - Microsoft Internet Explorer 5.x - Microsoft Windows 2003 Server Severity --------- Critical - Remote code execution, no user intervention Proof of Concept? ------------------ - http://freehost07.websamba.com/greyhats/sp2rc.htm - If an error is shown, press OK. This is normal. - Notice in your startup menu a new file called Microsoft Office.hta. When run, this file will download and launch a harmless executable (which includes a pretty neat fire animation) Michael Evanchik Relationship1 p: 914-921-4400 f: 914-921-6007 mailto:mevanchik@relationship1.com web: http://www.relationship1.com ############################################################################ ######### This Mail Was Scanned by 012.net Anti Virus Service - Powered by TrendMicro Interscan
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-Disclosure] Windows (XP SP2) Remote code execution with parameters, ShredderSub7 SecExpert |
|---|---|
| Next by Date: | [Full-Disclosure] Isecom, osstm related: CRG was busted yesterday, your_momma |
| Previous by Thread: | RE: [Full-Disclosure] YEY AGAIN Automatic remotecompromiseofInternetExplorer Service Pack 2 XP SP2, Michael Evanchik |
| Next by Thread: | RE: [Full-Disclosure] YEY AGAIN Automatic remote compromise ofInternetExplorer Service Pack 2 XP SP2, Michael Evanchik |
| Indexes: | [Date] [Thread] [Top] [All Lists] |