Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Outlook/HTML "proggie"

Re: Outlook/HTML "proggie"

From: Eric Chien <ecchien_at_JPS.NET>
Date: Fri, 2 Jun 2000 10:10:12 +0200

Hello,

It is amazing sometimes how much bandwidth someone can get and how much is
wasted. Very old news and patched months ago by Microsoft.
http://www.microsoft.com/technet/security/bulletin/ms99-032.asp

...Eric

At 11:33 PM 6/1/2000 +0300, methodman wrote:
> well... since everybody is so interested in what the SCR object is,
>i'm going to tell you... it is an activex control with the classID:
>06290BD5-48AA-11D2-8432-006008C3FBFC , it's name is actually gave it the id
>SCR). WSH has the classID called "Windows Scripting Host Shell Object",
>(Wscript.SHell - therefore i gave it the id WSH). about badblood... i
>didn't even hear about it until Thierry said it exists, same goes for the
>code written by Exxtreme. about the source code... if you are reading this
>through outlook check "thisreallyworks.txt" on your desktop :)). -- this
>only works if the security level is not set to "restriced sites zone"
> [ methodman ]
Received on Jun 02 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos