[FWD] THE SECRET OF THE MOST DANGEROUS HOLE IN IE HISTORY
ZXNet echo conference «zxnet.pc»
From Kirill Frolov → To All 23 January 2002
* RU.INTERNET (RU.INTERNET)
* Eugene Kostin, 2:5020/400 (22.01.2002 16:22)
*All
* THE SECRET OF THE MOST DANGEROUS HOLE IN IE HISTORY
01/18/2002
Microsoft REVEALED THE SECRET OF THE MOST DANGEROUS HOLE IN IE HISTORY
Microsoft has provided clarification regarding the real danger
a vulnerability in the Internet Explorer browser versions 5.5 and 6, discovered in
December 2001 by Online Solutions. Within a month from the date
hole detection, users had the opportunity to download the corresponding
patch.
As it turned out, this gap deserves the title of the most serious in the history of IE
and poses an extremely serious danger to users
Internet Explorer browser versions 5.5 and 6. The fact is that adding
characters %00 (the so-called “zero byte”) at the end of the file names,
hosted on the server, allowed you to run any applications on the side
client by simply adding to the above name characters
executable file.
For example, the client accesses a file called readme.txt%00prog.exe
can cause execution of the prog.exe file on the client side without starting
any dialog or warning windows.
Such a mechanism is an ideal opportunity to launch Trojan and
virus files downloaded by the client, for example, along with the mail
message, after the user on the client side simply runsA hyperlink is attached to this message.
Source: http://www.viruslist.com/index.html?tnews=1002&id=54081