exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

msNoGood.txt

msNoGood.txt
Posted Jan 19, 2005
Authored by Valentin Avram

It appears that the Microsoft patch released to fix the HHCTRL.OCX vulnerability discussed in MS05-001 can still be exploited using other IE bugs that are not patched.

tags | advisory
SHA-256 | cfbc753782aed6d9054b3947d4f7f8a765f39467a92023338ec8b4f26f03c149

msNoGood.txt

Change Mirror Download
Hi everybody.

Just wanted to point out that the patch Microsoft released to take care
of the HHCTRL.OCX vulnerability (MS05-001) is fixing just part of the
problem.

At least Windows XP Service Pack 1 and Windows 2000 Service Pack 4 are
still vulnerable to exploiting the HHCTRL vulnerability, by using
another IE bug not patched yet. I have successfully used the HHCTRL
exploit on an WinXP SP1 and Win2k SP4 uptodate today (Jan18-2005).

I won't release any technical information for now, i believe that most
of you already know this.

Service Pack 2 doesn't seem to allow this bypass i used. If anyone knows
of a way to bypass SP2 and still exploit the HHCTRL way, please let me
know, we'd like to let people know to be careful (even if they have SP2).

Thank you all for your time.

--
Valentin AVRAM
IT Security Engineer
GeCAD NET
Phone: +40-21-321.78.03
E-mail: vavram@gecadnet.ro
Web: www.gecadnet.ro
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close