Vulnerability Development mailing list archives

Re: Rather large MSIE-hole


From: "Paul D. Campbell" <antihero () sig9 com>
Date: Thu, 14 Mar 2002 11:08:36 -0800

Could you not create a batch file that housed the commands you wanted
to run
(with args) and just run the batch file?
I apologise if someone has already addressed this.

-Eric

You would probably be able to do this. However, you would first need
to place the batch file on the target machine. Then you would have to
sit around and hope the user visits your malicious site. Though, if
you have the capability to write to someone's harddrive you could do
something much nastier than this :)

Paul


Current thread: