Re: Is it possible to run a command on the client computer ?
- From: "Dag Sunde" <me@xxxxxxxxxxxx>
- Date: Fri, 25 May 2007 09:54:57 +0200
navti wrote:
On May 25, 5:13 am, Andrew Thompson <andrewtho...@xxxxxxxxx> wrote:<snipped/>
On May 25, 7:39 am, navti <nav...@xxxxxxxxx> wrote:
On May 24, 10:16 pm, -Lost <maventheextrawo...@xxxxxxxxxx> wrote:>...
navti wrote:
it all happened automatically without any intervention. i was
using win2k and ie6 at the time. i have since switched to mac os
x.
if ((JVM_vers[0]!=0)&&(JVM_vers[2]<3810))
{ ExploitNumber=1; }
else // if JVM = 5.0.3810.0 or higher
The (dreaded) MSVM.
he stole my files . i know this for a fact.
why would you think it was otherwise ? have you been living down a
mineshaft for the past 5 years ? never heard of xss ? are you in some
sort of state of denial ?
only an ignoramus would try and deny it was possible for a webserver
to compromise a client's machine.
my mistake is thinking javascript was enough . obviously it was a
combination of javascript, java, activex , php , xml etc etc
JavaScript, php, xml and etc. does not have *anything* to do with it!
The only way a webserver can compromise a client in the way you described
is eiter:
1.) A signed Java Applet where you explicitly have ansvered "Yes" when
asked if you wanted to let the applet run.
2.) A signed ActiveX control where you explicitly have ansvered "Yes"
when
asked if you wanted to let the control run.
3.) Any ActiveX control, and you have the security settings of your
browser
wide-open.
Neither PHP nor JavaScript is able to access your files.
--
Dag.
.
- Follow-Ups:
- References:
- Is it possible to run a command on the client computer ?
- From: navti
- Re: Is it possible to run a command on the client computer ?
- From: Lee
- Re: Is it possible to run a command on the client computer ?
- From: navti
- Re: Is it possible to run a command on the client computer ?
- From: Good Man
- Re: Is it possible to run a command on the client computer ?
- From: navti
- Re: Is it possible to run a command on the client computer ?
- From: Ivan Marsh
- Re: Is it possible to run a command on the client computer ?
- From: navti
- Re: Is it possible to run a command on the client computer ?
- From: -Lost
- Re: Is it possible to run a command on the client computer ?
- From: Andrew Thompson
- Re: Is it possible to run a command on the client computer ?
- From: navti
- Is it possible to run a command on the client computer ?
- Prev by Date: Re: Is it possible to run a command on the client computer ?
- Next by Date: help with javascript behaviours?
- Previous by thread: Re: Is it possible to run a command on the client computer ?
- Next by thread: Re: Is it possible to run a command on the client computer ?
- Index(es):
Relevant Pages
|
Loading