Vulnerability Development mailing list archives

Win32hlp exploit for : ":LINK overflow"


From: descript <descript () sv98 s0h cc>
Date: Sun, 9 Mar 2003 00:38:28 +0000

hi list,

In date Sunday, 9 March, 2003 1:00 AM s0h released an exploit : Win32hlp exploit for : ":LINK overflow"

Source : http://s0h.cc/exploit/s0h_Win32hlp.c
Binary : http://s0h.cc/exploit/s0h_Win32hlp.exe

Discovered by ThreaT <threat () s0h cc>.
Coded by ThreaT <threat () s0h cc>
Hompage : http://s0h.cc/~threat/

This exploit can trap a .CNT file (file with .HLP files) with the arbitrary code who can download and execute a trojan 
without user ask.

This exploit was tested on :
        - Windows 2000 PRO/SERVER (fr) SP0
        - Windows 2000 PRO/SERVER (fr) SP1
        - Windows 2000 PRO/SERVER (fr) SP2


Best regards,
descript <descript () s0h cc>
s0h - Skin of humanity
http://s0h.cc


Current thread: