Web Hack List

Top 10 winner

ActiveX Repurposing

Owning the Client without an Exploit

JavaScript uses the RDS.DataSpace ActiveX control to instantiate XMLHTTP, ADODB.Stream and Shell.Application, download an executable, save it to disk and run it. The author reports different IE6 and IE7 prompting behavior and confirms intentional omissions in the listing; comments discuss XP service-pack compatibility.

Record

Document
Owning the Client without an Exploit
Researcher
dean de beer
Published by
blog.carnal0wnage.com
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of dean de beer, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .