mailing list archives
MSIE->Findeath: break caller-based authorization
From: Liu Die Yu <liudieyuinchina () yahoo com cn>
Date: 10 Sep 2003 05:15:40 -0000
Findeath: break caller-based authorization.
("that's all" is end of file if you are in a hurry)
MS Internet Explorer: 6.0.2600.0000.xpclnt_qfe.021108-2107;
(So, it's far from fully patched.)
OS Ver: "Windows XP Cn ver"
(press CTRL+F and search for something.)
---> Findeath section
---> Findeath-MyPage file
window.open checks the root-caller's security id.
("root-caller" is some script which is not invoked by
my function can be called by the FIND
dialog(RES-protocol page in MYCOMPUTER zone):
hijack this function:
and ask the user to search for something.
at last, FIND dialog calls
while using the CTRL+F dialog, i suddenly remembered
he stated: if time can change others, time can also be
changed be others.
of course, i know the FIND dialog are calling some
methods in the main window obj,
so window obj can also play some tricks. (yeah.
einstein is not always a loser. :-) )
and then thanks to "GreyMagic" for "GreyMagic Security
he/they used function hijack. oh, just a reminder.
the Pull, dror, guninski, greymagic, sandblad and
of course, mom and dad.
from http://Umbrella.MX.TC on http://SafeCenter.NET
- MSIE->Findeath: break caller-based authorization Liu Die Yu (Sep 10)