Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 07-05-2004, 02:02 PM   #1
extreme
Confirmed User
 
Industry Role:
Join Date: Oct 2002
Location: lalaland
Posts: 2,120
anyone with a fully patched IE6..

.. does either of theese 2 links popup a cmd.exe window for you? Absolutely harmless test.

http://www.signupsluts.com/ie.html

http://www.signupsluts.com/ie2.html
extreme is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:04 PM   #2
David!
By the wrath of Agamemnon
 
David!'s Avatar
 
Industry Role:
Join Date: Apr 2004
Location: Miami
Posts: 6,501
2nd one popped up a window "attempting injection"
__________________
.
David! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:07 PM   #3
johnbosh
Confirmed User
 
Join Date: Aug 2002
Location: The Netherlands, Rotterdam
Posts: 8,965
first one loaded without problems, second one, same popup asPussyMan

Where are you testing it for?
johnbosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:12 PM   #4
Fabuleux
Confirmed User
 
Join Date: May 2003
Location: The Netherlands
Posts: 2,543
The first one is trying to use an exploit.
__________________
Fabuleux is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:12 PM   #5
the Shemp
congrats to the winners
 
the Shemp's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: Echo Beach
Posts: 10,891
Quote:
Originally posted by PussyMan
2nd one popped up a window "attempting injection"
ditto
the Shemp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:17 PM   #6
cambaby
So Fucking Banned
 
Join Date: Feb 2003
Location: CR
Posts: 3,141
Mozilla Firefox
cambaby is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:20 PM   #7
s9ann0
Confirmed User
 
Join Date: Sep 2001
Location: Boston
Posts: 4,873
nah doesn't run it
s9ann0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:21 PM   #8
extreme
Confirmed User
 
Industry Role:
Join Date: Oct 2002
Location: lalaland
Posts: 2,120
ok, that wasn't it though. It tries to execute "cmd.exe /c pause".

Testing for this but didn't get it to work:

http://seclists.org/lists/bugtraq/2004/Jul/0026.html

Last edited by extreme; 07-05-2004 at 02:23 PM..
extreme is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:22 PM   #9
HARDC0R3
Registered User
 
Join Date: Jun 2004
Posts: 14
2nd window: INJECTED

wtf are you doing to my browser
HARDC0R3 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:29 PM   #10
extreme
Confirmed User
 
Industry Role:
Join Date: Oct 2002
Location: lalaland
Posts: 2,120
Quote:
Originally posted by HARDC0R3
2nd window: INJECTED

wtf are you doing to my browser
That's just a normal java-scri-pt popup ... the exploit test is totally harmless + didn't even seem to work.

Apparently there's a way to bypass the latest IE securitypatch by using Shell.Application instead of ADODB.Stream (which the latest patch disabled).
extreme is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:32 PM   #11
Fabuleux
Confirmed User
 
Join Date: May 2003
Location: The Netherlands
Posts: 2,543
Quote:
Originally posted by extreme
That's just a normal java-scri-pt popup ... the exploit test is totally harmless + didn't even seem to work.

Apparently there's a way to bypass the latest IE securitypatch by using Shell.Application instead of ADODB.Stream (which the latest patch disabled).
No. it's not. The last patch I downloaded was 2 hours ago, my browser blocks both pages you submitted.
__________________
Fabuleux is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:34 PM   #12
Manowar
jellyfish  
 
Join Date: Dec 2003
Posts: 71,528
Quote:
Originally posted by PussyMan
2nd one tried popped up a window "attempting injection"
Manowar is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:36 PM   #13
extreme
Confirmed User
 
Industry Role:
Join Date: Oct 2002
Location: lalaland
Posts: 2,120
Quote:
Originally posted by Fabuleux
No. it's not. The last patch I downloaded was 2 hours ago, my browser blocks both pages you submitted.
Read my posts better. You're talking about the ADODB.Stream patch correct? Im talking about a possibility to bypass it, was mentioned on bugtraq. But didn't work for me and nobody else so looks like false alarm atm. Or if I got the exploit test wrong somehow.
extreme is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:38 PM   #14
David!
By the wrath of Agamemnon
 
David!'s Avatar
 
Industry Role:
Join Date: Apr 2004
Location: Miami
Posts: 6,501
WTF ????





























I got 20 Dollars bills coming out of my printer now !!
__________________
.

Last edited by David!; 07-05-2004 at 02:39 PM..
David! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 02:40 PM   #15
extreme
Confirmed User
 
Industry Role:
Join Date: Oct 2002
Location: lalaland
Posts: 2,120
Quote:
Originally posted by PussyMan
WTF ????

I got 20 Dollars bills coming out of my printer now !!
wooohooo, I deserve 50%!
extreme is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2004, 03:01 PM   #16
MattO
The O is for Oohhh
 
Join Date: Feb 2003
Location: AUSTIN TEJAS
Posts: 10,861
In the last couple of weeks I have seen a lot of submissions to my TGP with that injection code in it. I don't know what the hell whoever is submitting it is thinking like they'd get approved with that kind of bullshit.
MattO is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.