|
|||||||||||
|
RE: [Full-disclosure] SecNiche : Microsoft Internet Explorer Pop up Blocker Bypassing and Dos Vulnerability
From: Debasis Mohanty <debasis.mohanty.listmails(at)gmail.com>
Date: Wed Aug 15 2007 - 12:57:08 EDT
I don't see anything in the script that can bypass zone security and run successfully from internet zone. I am sure you have tested it locally and drawn conclusion that the script can execute from internet zone. To test the script from internet zone, you need to upload it to a webserver and try accessing via browser. Any VB/Java script will run from local security with a charm but if you can make it run from internet zone (without a prompt) then you found a holy grail. However I don't see anything in the script which can defeat zone security and access registry, hence no vulnerability. The best way to validate your work before posting publicly is, run it through the vendor or third party security sites like secunia or idefence. This would certainly save you from public embarrassment. -d -----Original Message----- Advisory : Microsoft Internet Explorer Pop up Blocker Bypassing and Dos Vulnerability Dated : 15 August 2007 Severity : Critical Explanation :
The vulnerability persists in the popup blocker functioning to allow
specific websites to execute
Detail Advisory :
Proof of Concept : Level 1 Infection Test http://www.secniche.org/misc/ie_pop_by_level1_test.zip
Test run fine locally as well with Web server [IIS] automated server
object calling. Infection
Regards
Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ Received on Wed Aug 15 15:35:56 2007 This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:12:07 EDT |
||||||||||
|
|||||||||||