mailing list archives
From: spinbad <spinbad.security () googlemail com>
Date: Fri, 23 Oct 2009 21:31:06 +0200
Attached you find a exploit module which can be used if a administrator
set the IE security zone setting "Initialize and script ActiveX controls not
marked as safe"
The default setting is "disabled", but I had two cases where it was enabled
the intranet zone in a large network, making it a perfect attack vector for
Hope you like it. Would be cool if someone buts it into the SVN.
- ie_unsafe_scripting spinbad (Oct 23)