Friday, January 9, 2009

IE 0Day "Print Table of Links"

According from 009, this kind of attacked triggered when users IE execute "Print Table of Links" and it called as (Cross-Zone Scripting).

Save the script below as html code, and open with Microsoft IE. Choose for printing and it will trigger calc.exe program.


You may download the executable code from http://www.blogjava.net/Files/baicker/calc.rar , save it to C:\ directory and rename to test.exe,Execute test.exe after rename it.
Please don't try to unzip it because the calc.rar already in PE file.

0 comments: