Vulnerability Development mailing list archives

Re: Outlook/HTML "proggie"


From: walter.williams () GENUITY COM (Walter Williams)
Date: Fri, 2 Jun 2000 08:25:59 -0400


It won't work if you have marked don't run activex scripts no matter what
security zone you have setup.
  -----Original Message-----
  From: VULN-DEV List [mailto:VULN-DEV () SECURITYFOCUS COM]On Behalf Of
methodman
  Sent: Thursday, June 01, 2000 4:33 PM
  To: VULN-DEV () SECURITYFOCUS COM
  Subject: Re: Outlook/HTML "proggie"

  well...
  since everybody is so interested in what the SCR object is, i'm going to
tell you...
  it is an activex control with the classID:
06290BD5-48AA-11D2-8432-006008C3FBFC ,
  it's name is actually SCRiptlet.typlib (that's why i gave it the id SCR).
WSH has the classID
  F935DC22-1CF0-11D0-ADB9-00C04FD58A0B and is called "Windows Scripting Host
Shell Object",
  (Wscript.SHell - therefore i gave it the id WSH).
  about badblood... i didn't even hear about it until Thierry said it
exists, same goes for the code written by Exxtreme.
  about the source code... if you are reading this through outlook check
"thisreallyworks.txt" on your desktop :)).
  -- this only works if the security level is not set to "restriced sites
zone"

  [ methodman ]


Current thread: