The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


IE 6 XML Patch Bypass


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Tue, 07 Oct 2003 22:11:37 +0800
From: Mindwarper * <mindwarper@linuxmail.org>
To: bugtraq@securityfocus.com
Subject: IE 6 XML Patch Bypass

IE 6 XML Patch Bypass

I have recently been playing around with the xml+windows media player exploit, and it 
seems that even with the new Microsoft patch applied, the vulnerability works.
I have tried it on 7 different people, on win2k and xp, and it worked everytime. 
The 8th person was using DAP (Download Acceselerator Plus), so it asked him if he 
wanted to download the executable. IE hacks like Dybuk Explorer are not affected by 
the vulnerability as well.

Here is a proof-of-concept:

http://mindlock.bestweb.net/wmp.htm

Note: this only works on people who have media player in C:\Program Files\Windows Media Player\ 
and version 9.

I am not 100% sure, but I believe that microsoft's new patch fixes the 401 bug. 
I tried using "HTTP/1.0 401 EVIL EVIL" so this may have been the reason for the patch bypass.

My solution would be to disable the media bar in IE 6. I explained how to do so in wmp.htm.


-----------------------------|
- Mindwarper                 |
- mindwarper@linuxmail.org   |
- http://mindlock.bestweb.net|
-----------------------------|

-- 
______________________________________________
http://www.linuxmail.org/
Now with e-mail forwarding for only US$5.95/yr

Powered by Outblaze

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру