Forums: Xp Exploit About Folder And Html - Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Xp Exploit About Folder And Html is this posted before?

#1 User is offline   zero-maitimax 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 309
  • Joined: 16-December 03

Posted 26 January 2004 - 05:01 AM

ppl new exploit in xp


if you change a html file in .folder . xp will change the icoon als a map.

but

if you dubbel click on it it open as a html. you can put in a html jave script that excute an exe file..

the exploit is ver high becaurs program's like winzip see it as a folder



some jave script
http://www.malware.c...e-cute-html.zip
0

#2 User is offline   boshcash 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 461
  • Joined: 09-October 03

Posted 26 January 2004 - 06:08 AM

i dont understand what u r saying but i think these are oldies ..
0

#3 Guest_usanet21_*

  • Group: Guests

Posted 26 January 2004 - 06:14 AM

yeah man..agrees...i cant understand wat he is sayin,
zero-maitimax, can u pls tell me step by step how to change a html file and write a javascript to execute an exe file. sorry, i really dont understand
0

#4 User is offline   zero-maitimax 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 309
  • Joined: 16-December 03

Posted 26 January 2004 - 06:19 AM

oke


wel you justed make a html file with jave script in it.. and in the jave script you put a exe file (trojan)

now you change the .html to .folder


now the icoon change in to a folder icoon..


but if you dubbel klik on the folder it open de orignaal html file..

and excute the exe(trojan)



if you pack this folder in winzip you still see a folder icoon even in winzip .. but again if you dubbel klik on it will excute the origanaal html file
0

#5 Guest_sysadmin_*

  • Group: Guests

Posted 26 January 2004 - 06:26 AM

Hallo zero-maitimax,

i tried it out with WINZIP 8.0 and it works like you said!!

Winzip works with that file like a "folder" and excute it, just within a trojan.

Bye, sysadmin
0

#6 User is offline   zero-maitimax 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 309
  • Joined: 16-December 03

Posted 26 January 2004 - 06:28 AM

tnx you have traid it :D


i'm good :P
0

#7 User is offline   EXPLOiTED 

  • Sergeant
  • Icon
  • Group: Members
  • Posts: 236
  • Joined: 23-October 03

Posted 26 January 2004 - 06:29 AM

ok that makes sense. but when what exe are u gonna exec?...i hope OS's dont come with premade trojans on them. Would that mean you have to get the trojan u wanna exec on their system as well?
0

#8 Guest_sysadmin_*

  • Group: Guests

Posted 26 January 2004 - 06:40 AM

zero-maitimax, on Jan 26 2004, 02:28 PM, said:

tnx you have traid it :D


i'm good :P

Hey zero-maitimax,

you are so goooood ! ! ! :lol:

Bey, sysadmin
0

#9 User is offline   zero-maitimax 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 309
  • Joined: 16-December 03

Posted 26 January 2004 - 06:50 AM

some more info
http://lists.netsys....-January/016115. html

example (TrojanDropper.JS.Mimail.B)
http://www.malware.com/my.pics.zip
0

#10 Guest_sysadmin_*

  • Group: Guests

Posted 26 January 2004 - 06:59 AM

zero-maitimax, on Jan 26 2004, 02:50 PM, said:


Hello zero-maitimax,

this link does not match. :(

Bye, sysadmin
0

#11 User is offline   larsbruggie 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 29
  • Joined: 19-August 03

Posted 26 January 2004 - 07:13 AM

I was so n00b that I opened illmob's my picture.folder , now I am infected
0

#12 Guest_sysadmin_*

  • Group: Guests

Posted 26 January 2004 - 07:17 AM

Hallo larsbruggiem,

:(

Next time its better to "read" the posts. :(

Bye, sysadmin
0

#13 User is offline   zero-maitimax 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 309
  • Joined: 16-December 03

Posted 26 January 2004 - 07:23 AM

http://lists.netsys....ary/016115.html


larsbruggie i'm sorry for yeah..



i found more stuff


.dvd
.audiocd
.mapimail
.mydocs


solution i found is HKEY_CLASSES_ROOT/.folder delete it.. ( don't know if it is wrong but the exploit doesn't excist no more at my machiene)
0

#14 User is offline   hdlgp 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 26
  • Joined: 29-November 03

Posted 26 January 2004 - 10:14 AM

I prove this exploit and works, :D
0

#15 Guest_T3cHn0b0y_*

  • Group: Guests

Posted 26 January 2004 - 11:25 AM

It does indeed! Im deleting that regkey right now! Thnx 4 the info m8! ;)
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting