This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Poc For Arbitrary Command Execution With Ie+xpsp2

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Secunia announced PoC for arbitrary command execution with IE+XPSP2:

- http://secunia.com/internet_explorer_comma…erability_test/

…yep, it fails, which means:

"…Any web site will be able to take total control of your computer without any interaction from you.
The "Internet Explorer Command Execution Vulnerability" allows an attacker to execute arbitrary commands/programs on your computer. Exploitation is only limited by the imagination of the attacker
…"


:ph34r: :ph34r: :ph34r:
FYI…from the Internet Storm Center:

- http://isc.sans.org/diary.php?date=2005-01-09
Updated January 9th 2005 23:45 UTC
"…The vulnerability is yet another cross-site scripting vulnerability. It will allow remote code execution on a victim's system just by visiting the website. The Storm Center has received one email of such a site and confirmed that it was actively using the exploit to attempt to download XP.exe from several locations. Currently vulnerable is IE6 on a fully patched WindowsXP system. As of now, there is no patch available. I know Symantec is detecting this as bloodhound.exploit.21 from what I have observed, but I'm not sure what other antivirus software is doing. It is advisable to keep your antivirus software updated and move to another web browser if possible. For more information, please see http://secunia.com/advisories/12889/ …"

:ph34r: