Internet Explorer silent software delivery (remote exploit)
14th Aug 2002 [SBWID-5628]

	IE silent software delivery (remote exploit)


	Internet Exlorer 6


	http_equiv of malware [] found :

	Yet another silent delivery and installation of  an  executable  on  the
	target computer using Internet  Exlorer  6.  This  can  be  achieved  by
	reversing the following:



	HTM. In order to to achieve the required  results  as  outlined  in  the
	above, we must determine the location of  the  Temporary  Internet  File
	[TIF] folders. This can only be achieved if we can  physically  open  up
	our file from within and read its location. Technically  that  can  only
	be achieved if  we  have  a  security  dialogue  prompt  asking  us  for
	permission. If we elect to open  the  file  through  acceptance  of  the
	security warning dialogue, it is opened from within the TIF by  whatever
	program is associated with that file.


	Okay. HTM. HTM files are associated with  Internet  Explorer.  We  force
	our *.htm file open via a combination of server  `misconfiguration`  and
	our PHP 'package' as below:


	function malware()


	header("Content-type: text/html");

	header("Content-Disposition: attachment");

	echo base64_decode(



















	{ malware(); }

	PHP ?>


	  <iframe src=<? echo $PHP_SELF ?> width=1 height=1>


	Where our PHP 'package' contains our now  run-of-the-mill  scripting  to
	determine our TIF location and our old friend the trojanised *.chm  file
	as follows:

	<img dynsrc="" width=1





	// 7.02.02


	function malware()





	document.write('<FORM name="malware"



	document.write('<form><input type="hidden" size="40" maxlength="80"







	note: file path for *.chm must be long as we are now operating  off  the
	server and from within the TIF

	What this does is  generate  the  default  security  warning  for  *.htm

	[screen shot: 7KB]


	Should we elect to open it, we are once again able to determine our  TIF
	location where our *.chm is now residing too and fire our  scripting  to
	locate and call it.

	[screen shot: 7KB]



	1.    As     indicated     this     is     the     reverse     for     : . In this instance the  default
	is the security warning which should be  disengaged  to  allow  this  to

	2 Tested series of win98 machines, Internet Explorer  6.0.2600  and  all
	of its bandages

	3. We anxiously await the release of Internet Explorer 6 SP1.


	None yet.

