Bugtraq mailing list archives

Re: Exploit in IE6,7


From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Tue, 29 Jan 2008 11:25:42 +1300

r2t () hotmail it wrote:

Discovred By : Hasadya Raed
E-mail : r2t () hotmail it , Hacker_Web () w cn
-----------------------------------------
Exploit : Internet Explorer 6,7
-----------------------------------------
Code : 
<<yawn...>> 

Nothing new here, move along please...

This is an old, and once commonly-used in the wild, implementation of 
the so-called "MDAC vulnerability" patched in MS06-014.

Some trivial Googling turns up instances of this precise code being 
discussed in online fora in July 2006.

Repeating oneself:

Discovred By : Hasadya Raed

Hasadya:

In what meaningful sense did you "discovr" this?

Why do you think we might care?

And do you have you any idea of whether and/or how it actually works?


Regards,

Nick FitzGerald


Current thread: