Full Disclosure mailing list archives

RE: how do they do it???


From: "Bojan Zdrnja" <Bojan.Zdrnja () LSS hr>
Date: Fri, 11 Jul 2003 17:14:41 +1200



-----Original Message-----
From: full-disclosure-admin () lists netsys com 
[mailto:full-disclosure-admin () lists netsys com] On Behalf Of 
Thor Larholm
Sent: Friday, 11 July 2003 7:43 a.m.
To: full-disclosure () lists netsys com; zorkshin () tampabay rr com
Subject: Re: [Full-disclosure] how do they do it???


From: <zorkshin () tampabay rr com>
http://www.albinoblacksheep.com/text/cupholder.php

how do you think they do it in PHP?

Thank you for confirming that you have NOT installed the MS03-021 patch
[1] for
Windows Media Player, which among others removes the ability to eject CD
drives
using the WMP ActiveX control. I can now safely assume that you are
vulnerable
to several vulnerabilities.

Do you want an HTML email? ;)

Well, what's very interesting, this Web page opens CD tray on my computer,
which is *FULLY* updated Windows XP SP1, with all patches.

Both WU and HFNetChk don't list any patch missing. I guess something is
wrong there.

Best regards,

Bojan Zdrnja

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: