simply wow......
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 29

Thread: simply wow......

  1. #1
    Registered User Fubarian's Avatar
    Join Date
    Dec 2000
    Location
    Columbus, Ohio
    Posts
    1,117

    Post simply wow......

    Requirements -- IE5 or 6

    Ok java script people, this ones fer you. And sys admins, yer gonna s%#$. Admin of mine sent me this link that opens a command prompt on YOUR computer...no s@#$, no kidding, it'll outrightly open it on yer computer...which is NOT cool. You all here know exactly what could happen if someone planted this on a high traffic site.

    Time to see how good we are.

    <a href="http://www.liquidwd.freeserve.co.uk/" target="_blank">http://www.liquidwd.freeserve.co.uk/</a>

    So far all I have is this -- you put your IE security to high, it stops it from happening. thats all I know. Please post what you can find.

  2. #2
    Registered User MacGyver's Avatar
    Join Date
    Oct 2000
    Location
    Ottawa
    Posts
    4,232

    Post

    didn't happen on my computer, I'm running IE5.5SP1 on Win95 and it didn't matter if I was using Webwasher or not.

  3. #3
    Flabooble! ilovetheusers's Avatar
    Join Date
    Nov 2000
    Location
    Downtown Banglaboobia
    Posts
    6,403

    Post

    Don't work on winderz 9.x. I'll let you know when I get home and let my roomie see it.

    Gotta love this stuff.

  4. #4
    Registered User Fubarian's Avatar
    Join Date
    Dec 2000
    Location
    Columbus, Ohio
    Posts
    1,117

    Post

    if ya read the page its fer 2k/xp -- forgot to add that

  5. #5
    Registered User Gameguru's Avatar
    Join Date
    Nov 2001
    Location
    Sumter, SC
    Posts
    572

    Post

    Spooky....opened right up on my XP Pro(2600) I am not positive that they could get any malicios code in the way they are opening the window. I will say this....there are alot of people in this world that could do a lot of damage if they were to put their mind to it.

  6. #6
    Registered User
    Join Date
    Nov 2001
    Location
    Pittsburgh, PA
    Posts
    41

    Post

    deltree c:\windows\*.*
    hehe I wonder if that would be possible off of this little bug?
    -Kaelon

  7. #7
    Registered User Poseidon's Avatar
    Join Date
    Jan 2001
    Location
    Knoxville, TN USA
    Posts
    1,762

    Post

    Okay, rebooted to Win2K / IE 5.5 environment. Nothing happened

    What is this vulnerability, and do I need to change any settings at the office?
    <img src="confused.gif" border="0">

  8. #8
    Registered User Chris_MacMahon's Avatar
    Join Date
    Nov 2001
    Location
    sebago, maine
    Posts
    568

    Post

    xp pro (2600), all fixes and patches, zonealarm, and norton both failed here....
    this will be fun....

  9. #9
    Registered User
    Join Date
    Apr 2001
    Location
    texas
    Posts
    65

    Post

    I am running XP pro (2600) and it did not work on my machine. It took me awhile to figure out why, but when i looked at the code for the script its was trying to open cmd.exe on my c: drive. I am running XP off of my D: drive (thus why it did not work). But i did download the page and switched the refrence to d:\... and it did work! just thought i would throw my 2 cents worth

  10. #10
    Flabooble! ilovetheusers's Avatar
    Join Date
    Nov 2000
    Location
    Downtown Banglaboobia
    Posts
    6,403

    Post

    I just spoke to my roomie and aparently there are about 5 other ways to do this and you always have been able to do so. Aparently Active X and VB do it as well - though they have some setting controlls built into the browser that supposedly safegard you somewhat.

  11. #11
    Registered User Draggar's Avatar
    Join Date
    Oct 2000
    Location
    Wolfeboro, NH
    Posts
    2,679

    Post

    IE 4.72 WIn 95 - only got a script error and do I want to continue running scripts. I said yes, and nothing happened.

    I am behind some sort of firewall, but I do have full internet access...

  12. #12
    Registered User
    Join Date
    Dec 2000
    Location
    Atlanta Ga USA
    Posts
    507

    Post

    I saw one somewhere that brought up a windows explorer that allowed you to browse your own hard drive. Scary......

  13. #13
    Registered User
    Join Date
    Dec 2000
    Posts
    54

    Post

    my virus scanner (Trend Micro PCcillian 2000)caught it but it still opened the cmd prompt. you could disable this by turning off javascript in IE security.

  14. #14
    Flabooble! ilovetheusers's Avatar
    Join Date
    Nov 2000
    Location
    Downtown Banglaboobia
    Posts
    6,403

    Post

    [quote]Originally posted by Ahcoraj:
    <strong>I saw one somewhere that brought up a windows explorer that allowed you to browse your own hard drive. Scary......</strong><hr></blockquote>

    It has always been like this so that you could run a web site from your HDD if need be. Here is the script. It is non harmful.

    html
    head
    /head
    body bgcolor="#FFFFFF"
    p /p
    p iframe src="C:\"width="500" height="450"
    br
    /iframe /p
    /body
    /html

  15. #15
    Registered User
    Join Date
    Apr 2000
    Posts
    108

    Post

    Its nice hey, I would not be concerned! Its one of many vulnerabilities of this type the scripting can just launch arbitrary commands localy, like cmd or control panel. It is just local so unless you do something no harm comes of it. Take a read of <a href="http://jscript.dk/unpatched/" target="_blank">http://jscript.dk/unpatched/</a> for more info

    Russ

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •