[FWD] THE SECRET OF THE MOST DANGEROUS HOLE IN IE HISTORY

ZXNet echo conference «zxnet.pc»

From Kirill Frolov To All 23 January 2002

* RU.INTERNET (RU.INTERNET) * Eugene Kostin, 2:5020/400 (22.01.2002 16:22) *All * THE SECRET OF THE MOST DANGEROUS HOLE IN IE HISTORY 01/18/2002 Microsoft REVEALED THE SECRET OF THE MOST DANGEROUS HOLE IN IE HISTORY Microsoft has provided clarification regarding the real danger a vulnerability in the Internet Explorer browser versions 5.5 and 6, discovered in December 2001 by Online Solutions. Within a month from the date hole detection, users had the opportunity to download the corresponding patch. As it turned out, this gap deserves the title of the most serious in the history of IE and poses an extremely serious danger to users Internet Explorer browser versions 5.5 and 6. The fact is that adding characters %00 (the so-called “zero byte”) at the end of the file names, hosted on the server, allowed you to run any applications on the side client by simply adding to the above name characters executable file. For example, the client accesses a file called readme.txt%00prog.exe can cause execution of the prog.exe file on the client side without starting any dialog or warning windows. Such a mechanism is an ideal opportunity to launch Trojan and virus files downloaded by the client, for example, along with the mail message, after the user on the client side simply runsA hyperlink is attached to this message. Source: http://www.viruslist.com/index.html?tnews=1002&id=54081