[<prev] [next>] [day] [month] [year] [list]
Message-ID: <039c01c4ec66$f2b67680$6702a8c0@AlanPickel.com>
Date: Mon, 27 Dec 2004 17:53:57 -0500
From: "Michael Evanchik" <Mike@...haelEvanchik.com>
To: <bugtraq@...urityfocus.com>,
<NTBUGTRAQ@...TSERV.NTBUGTRAQ.COM>,
<vulnwatch@...nwatch.org>,
<full-disclosure@...ts.netsys.com>,
<Exploits@...tik.com>,
<Vuln@...tik.com>,
<send-us-news-tips@...t.com>
Subject: BUG FIX Remote compromise of Internet Explorer Service Pack 2 XP SP2
Had a mistake in my code o well. Works now
PoC: http://www.michaelevanchik.com/security/microsoft/ie/xss/index.html
http://www.michaelevanchik.com/security/microsoft/ie/xss/writehta.txt <-- avp's should add this
Here is some new adodb code AVP's should add. No longer needed to connect to external source. Malicious recordset can be built locally.
www.michaelevanchik.com
Powered by blists - more mailing lists