[prev in list] [next in list] [prev in thread] [next in thread] 

List:       ntbugtraq
Subject:    Re: HijackClick 3
From:       Drew Copley <dcopley () EEYE ! COM>
Date:       2004-07-13 19:00:46
Message-ID: FCAD9F541A8E8A44881527A6792F892C3080A6 () owa ! eeye ! com
[Download RAW message or body]

 

> -----Original Message-----
> From: Thor Larholm [mailto:tlarholm@pivx.com] 
> Sent: Tuesday, July 13, 2004 11:04 AM
> To: Windows NTBugtraq Mailing List
> Cc: Drew Copley
> Subject: RE: HijackClick 3
> 
> > From: Drew Copley
> > In fact, I don't think there has been a bug in about ten
> > months (coincidentally) that does not rely on either Jelmer's
> > adodb bug or your shell.application bug.
> 
> I'm sorry, but did everybody suddenly forget about codeBase command
> execution? Use a non-existant GUID for your OBJECT's classid and point
> the codeBase attribute to the executable you want launched.

You can not pass parameters to the command line app. 

You can run calc.exe or whatever, sure, but that is just a toy.

If you are aware of an open bug that allows this to be
exploited to run code of an attacker's choice, let me know.

(Not to mention that they have long since restricted the object
tag.)

I am surprised no one can name such a bug. I don't even involve
IE in my job much. 

Ten months... to be specific, actually, it is longer. Since last
August. Almost a year. Surely, I am wrong.

I guess Brett Moore's just released bug breaks this. Though,
it might be said Jouko's Outlook issue did. Two seasoned 
professionals.

Anyway, someone correct me here.

<snip>

-----
NTBugtraq Editor's Note:

Want to reply to the person who sent this message? This list is configured such that \
just hitting reply is going to result in the message coming to the list, not to the \
individual who sent the message. This was done to help reduce the number of Out of \
Office messages posters received. So if you want to send a reply just to the poster, \
you'll have to copy their email address out of the message and place it in your TO: \
                field.
-----


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic