Announcement

Collapse
No announcement yet.

Yet another IE vulnerability

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Yet another IE vulnerability

    But this one's kind of fun... it corrupts the contents of the address bar with a null character, which allows its contents be spoofed:

    http://zapthedingbat.com/security/ex01/vun1.htm
    45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B0
    45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B1
    [ redacted ]

  • #2
    This small exploit becomes handy in the Fruad division. he he he.

    Comment


    • #3
      I dont Get it.

      I dont understand how you do it. The whole http://User@Domain Is that a www address? Or what does that mean?

      Comment


      • #4
        Originally posted by Sparks-Kelly
        I dont understand how you do it. The whole http://User@Domain Is that a www address? Or what does that mean?
        IE has a UTF-16 address bar, and consequently it's valid for certain bytes to have a value of zero. However, clearly some of the display code is using zero terminated strings. Consequently, any part of the URL which lies after the zero is truncated.
        45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B0
        45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B1
        [ redacted ]

        Comment


        • #5
          Originally posted by Sparks-Kelly
          I dont understand how you do it. The whole http://User@Domain Is that a www address? Or what does that mean?
          How long have you been using a computer? Or the internet?
          "It is difficult not to wonder whether that combination of elements which produces a machine for labor does not create also a soul of sorts, a dull resentful metallic will, which can rebel at times". Pearl S. Buck

          Comment


          • #6
            Originally posted by Sparks-Kelly
            I dont understand how you do it. The whole http://User@Domain Is that a www address? Or what does that mean?
            If you pop open mozilla or netscape and visit that webpage, then click the little button that sends you to supposedly microsoft, it will essentailly take you to
            http://www.microsoft.com%01@zapthedi.../ex01/vun2.htm
            instead.

            the possibilities for exploitation are endless.
            Im just here to lurk around till i find something interesting. - Sleep is for the weak.

            Comment


            • #7
              Originally posted by GidGreen
              If you pop open mozilla or netscape and visit that webpage, then click the little button that sends you to supposedly microsoft, it will essentailly take you to
              http://www.microsoft.com%01@zapthedi.../ex01/vun2.htm
              instead.

              the possibilities for exploitation are endless.
              Ok Thank you. That helps alot. I have been using the Internet for a long time but I just didn't get it that well.

              Comment


              • #8
                the only problem is up to date virus definitions throw up a message indicating a spoofed url. also, latest windows updates prevent this from working

                Comment


                • #9
                  Originally posted by stingerbee
                  the only problem is up to date virus definitions throw up a message indicating a spoofed url. also, latest windows updates prevent this from working
                  Well... Yes. That's the point of patching your system.

                  As for the AV detection, AV is used for a lot of things it shouldn't be. That's a whole other can of worms, though.

                  Comment


                  • #10
                    Originally posted by skroo
                    As for the AV detection, AV is used for a lot of things it shouldn't be. That's a whole other can of worms, though.
                    Can of Worms... Good pun.

                    Comment


                    • #11
                      I knew that patch would affect me porno surfing wise and buggy.

                      Thank god I use firebird.

                      Hm
                      Hm

                      Comment

                      Working...
                      X