Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Vuln-Dev
[Top] [All Lists]

Re: Re: RE: playing for fun with <=IE7

Subject: Re: Re: RE: playing for fun with <=IE7
Date: 25 Oct 2007 15:58:16 -0000
Hi there
Nop it wont work.
http://dams083.free.fr/tmp/putty.exe?explorer.exe
the first .exe extension will be overwriten by
the second one . then it will be putty.exe anyways.

"avivra" did mention that he was able to use this bypass to automate the PDF 
attack vector
found by GNUCitizen's pdp
http://aviv.raffon.net/2007/10/15/BackFromTheDead.aspx

he also did mention that cyber_flash found the same kind of vuln on IE6 sp2 3 
years ago.

thanks to him for theses precisions.

i was also able to reproduce the pdp(gnucitizen) pdf 0days remotly without any 
promt with IE7
using the avivra idea/exemple showed on his video
here's a live exemple:
http://dams083.free.fr/pdf_poc.exe?1.pdf
pdf is open , calc.exe is launched no promt .

we can imagine the impact with a:
-permanent Xss
-malicious webpage
-worm
-etc 

regards laurent gaffié

//sorry for the delay.

<Prev in Thread] Current Thread [Next in Thread>