Skip to main content

Hmm, let's start a command shell...

posted onFebruary 20, 2002
by hitbsecnews

Kk ok call me stupid if you have seen this somewhere else or its been reported earlier (not that I remember, but hey!) The point is, if its been reported earlier why is it still an issue?

Thanks to Jelte (I think LOL) for sending me a link that appears to be able to manipulate the command shell in Windows 2000, XP and possibly Windows Me granted I don't know anyone that uses Me so lets concentrate on the NT platforms. This link when opened will start your command shell (I tested it and its not malicious) on Win2k/XP in IE5/6 (I have the latest version installed with all the patches). When looking at the source it appears to be quite simple yet effective for the people who could misuse it. It simply calls via javascripting the command prompt. Others could let it do a whole lot more.

I decided to submit an error report and bug email to Microsoft. I do not expect to hear anything from them but if I do I will post the response here. come on Microsoft close off that browser! It may kick Netscapes ass, but its no good to anyone with gaping holes in it. If anyone can shed more light on this "feature" please feel free to comment, maybe you could tell me why privacy settings in IE6 do not include privacy to the command shell and file system at default!

URL : http://www.liquidwd.freeserve.co.uk/

From : http://www.neowin.net

This certainly posses a great security threat to those who use IE browsers with Admin accounts. :)

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th