| 软件名称: | 
 execdror6-demo.zip | 
 
 
| 文件类型: | 
  | 
 
  
 | 
 
 
| 界面语言: | 
 简体中文 | 
 
 
| 软件类型: | 
 国产软件 | 
 
 
| 运行环境: | 
 WinNT/2K/Xp | 
 
 
| 授权方式: | 
 共享软件 | 
 
 
| 软件大小: | 
 25.09K | 
 
 
| 软件等级: | 
 ★★★★☆ | 
 
 
| 发布时间: | 
 2003-12-05 | 
 
 
| 官方网址: | 
 http://www.safechina.net 作者:vitter  | 
 
 
| 演示网址: | 
   | 
 
 
| 软件说明: | 
  | 
 
 
 
IE Remote Compromise by Getting Cache Location 
 
[tested] 
OS:WinXp, CN version 
Microsoft Internet Explorer v6.Sp1;ms03-048 up-to-date on 2003/11/16 
 
[overview] 
With the help of LocalZoneInCache(refer to "[technical details]" part), an attacker can compromise a user's system even though the user has: 
1. Customized IE cache directory, 
2. Applied MS03-048 patch, 
3. Set killbit for ADODB.STREAM ActiveX. 
 
[Workaround] 
Disable Active Scripting in INTERNET zone, so HTML page opened in the cache can't send information back to the attacker. 
 
[Greetings] 
greetings to: 
Drew Copley, dror, guninski, vadim and mkill. 
 
----- 
all mentioned resources can always be found at UMBRELLA.MX.TC 
 
[people] 
LiuDieyuinchina [N0-@-Sp2m] yahoo.com.cn 
UMBRELLA.MX.TC ==> How to contact "Liu Die Yu" 
 
[Employment] 
I would like to work professionally as a security researcher/bug finder. 
 
微软尚未发布补丁 
 | 
 
  | 
 
 
| 下载地址: | 
 进入下载地址列表
  | 
 
 
| 下载说明: | 
☉推荐使用网际快车下载本站软件,使用 WinRAR v3.10 以上版本解压本站软件。 
☉如果这个软件总是不能下载的请点击报告错误,谢谢合作!! 
☉下载本站资源,如果服务器暂不能下载请过一段时间重试! 
☉如果遇到什么问题,请到本站论坛去咨寻,我们将在那里提供更多 、更好的资源! 
☉本站提供的一些商业软件是供学习研究之用,如用于商业用途,请购买正版。  | 
 
  | 
 
 
 
[ 推荐] 
[ 评论(0条)] [返回顶部] [打印本页] 
[关闭窗口]    | 
 
 
|  
 | 
 
 
|   | 
 
  | 
 
  
 | 
 
        
  | 
  | 
推荐广告 | 
 
  | 
 
  | 
 
| 
		
		
 | 
 
 
 |