[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <55131797.20051118134826@Zoller.lu>
Date: Fri Nov 18 12:48:41 2005
From: Thierry at Zoller.lu (Thierry Zoller)
Subject: Re: another filename bypass vulnerability -
fromcmd.exe
Dear barabas mutsonline,
bm> Let's imagine there's an IE bug (quite hard to imagine, but ok)
bm> ....
bm> bm> adrianlima.gif and execute it using wsscript shell object run cmd /c adrianalima.gif (in vbs e.g.)
bm> just a thought, haven't tested it nor have I written l33t PoC :p
Thanks, nice, haven't thought of this :)
--
http://secdev.zoller.lu
Thierry Zoller
Powered by blists - more mailing lists