RE: playing for fun with <=IE7

看板Bugtraq作者時間18年前 (2007/10/16 06:09), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/4 (看更多)
It is interesting. I've even confirmed the behavior with IE 7 in Vista. Although the real concern is if it could be used in an exploitation?=20 The examples below aren't exploitable...just interesting outcomes. Roger ***************************************************************** *Roger A. Grimes, InfoWorld, Security Columnist=20 *CPA, CISSP, CISA, MCSE: Security (2000/2003), CEH, yada...yada... *email: roger_grimes@infoworld.com or roger@banneretcs.com *Author of Windows Vista Security: Securing Vista Against Malicious = Attacks (Wiley) *http://www.amazon.com/Windows-Vista-Security-Securing-Malicious/dp/04701= 01555 ***************************************************************** -----Original Message----- From: laurent.gaffie@gmail.com [mailto:laurent.gaffie@gmail.com]=20 Sent: Friday, October 12, 2007 4:34 PM To: bugtraq@securityfocus.com Subject: playing for fun with <=3DIE7 playing for fun with <=3DIE7 Impact: who knows ... Fix Available: no ------------------------------------------------------- 1) Bug 2) Proof of concept 3)Conclusion =3D=3D=3D=3D=3D=3D 1) Bug=20 =3D=3D=3D=3D=3D=3D it's possible to bypass the extension filter of <=3DIE7 this can result = by downloading an arbitrary exe file=20 =3D=3D=3D=3D=3D 2)proof of concept =3D=3D=3D=3D=3D let's take this exemple : http://dams083.free.fr/tmp/putty.exe this is simply putty . you click on this and then you will be prompted for downloading the = file. but what about if we do : http://dams083.free.fr/tmp/putty.exe?1.txt .... the .exe is showed. now let's go a bit ahead : http://dams083.free.fr/tmp/putty.exe?1.cda wow my .exe is downloaded directly and located in temporary files ( and = """opened""" by windows media player). works with theses extension : ..log ..dif ..sol ..htt ..itpc ..itms ..dvr-ms ..dib ..asf ..tif etc ... =3D=3D=3D=3D=3D 5) Conclusion =3D=3D=3D=3D=3D this is very funny , because actually it only works for .exe extensions. ..COM , .PIF , etc you CANT do this. ( overwrite the extension , and = then bypass the filter) i guess we can wonder what the heck. =20 regards laurent gaffi=E9
文章代碼(AID): #174-KV00 (Bugtraq)
文章代碼(AID): #174-KV00 (Bugtraq)