what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

IE6XMLbypass.txt

IE6XMLbypass.txt
Posted Oct 7, 2003
Authored by Mindwarper | Site mindlock.bestweb.net

The current patch fix for the Internet Explorer 6 XML bypass is faulty and still allows a remote web site to maliciously force IE to replace files on the underlying client system.

tags | advisory, remote, web
SHA-256 | 6d210eb5a6b46fd9b6b6c1f97c07ceb3e3762953328aa745c0211b913e84cf1c

IE6XMLbypass.txt

Change Mirror Download

IE 6 XML Patch Bypass

I have recently been playing around with the xml+windows media player exploit, and it
seems that even with the new Microsoft patch applied, the vulnerability works.
I have tried it on 7 different people, on win2k and xp, and it worked everytime.
The 8th person was using DAP (Download Acceselerator Plus), so it asked him if he
wanted to download the executable. IE hacks like Dybuk Explorer are not affected by
the vulnerability as well.

Here is a proof-of-concept:

https://mindlock.bestweb.net/wmp.htm

Note: this only works on people who have media player in C:\Program Files\Windows Media Player\
and version 9.

I am not 100% sure, but I believe that microsoft's new patch fixes the 401 bug.
I tried using "HTTP/1.0 401 EVIL EVIL" so this may have been the reason for the patch bypass.

My solution would be to disable the media bar in IE 6. I explained how to do so in wmp.htm.


-----------------------------|
- Mindwarper |
- mindwarper@linuxmail.org |
- https://mindlock.bestweb.net|
-----------------------------|

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close