<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; modal-dialog</title>
	<atom:link href="http://www.darknet.org.uk/tag/modal-dialog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Proof of Concept for Internet Explorer Modal Dialog Exploit</title>
		<link>http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/</link>
		<comments>http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/#comments</comments>
		<pubDate>Tue, 02 May 2006 03:32:48 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[internet-exploder]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[modal-dialog]]></category>
		<category><![CDATA[proof-of-concept]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/</guid>
		<description><![CDATA[Pretty interesting and imaginative way to exploit the flaw in IE&#8230;yeah I know linked to ActiveX again, all the more reason to use Firefox right? It just shows that the browser really is a point of entry, this could be useful for a penetration test, another way to show how easy it is to get [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Pretty interesting and imaginative way to exploit the flaw in IE&#8230;yeah I know linked to ActiveX again, all the more reason to use Firefox right?</p>
<p>It just shows that the browser really is a point of entry, this could be useful for a penetration test, another way to show how easy it is to get in via internet explorer, the frequency with which IE exploits have been coming out recently is scarier than normal.</p>
<blockquote><p>A particular scenario was identified that involved the exploitation of the modal ActiveX prompt delivered by some systems.  The user is asked to type a certain string of characters (ala captcha).  A prompt will be displayed (hopefully during the time the user is typing the string) to install the Microsoft Surround Video Control.</p>
<p>If you&#8217;re still typing the &#8220;captcha&#8221; when the prompt appears, you&#8217;ll install the control.  This works as advertised against all systems EXCEPT Windows XP SP2 and Windows Server 2003 SP1.  If the software you install hoses your box, just remember that it&#8217;s signed by Microsoft.  In<br />
other words&#8230; don&#8217;t look at me.</p></blockquote>
<p>You can check the PoC here:</p>
<p><a href="http://www.darknet.org.uk/content/ie_modal_test.html">Proof of Concept for IE Modal Dialog Issue</a></p>
<p>It just crashes IE for me, I&#8217;m not sure if it&#8217;s a null pointer or what, but I&#8217;m sure there&#8217;s some way to exploit it to take over the machine, it&#8217;s a another vulnerability, which usually can be mashed together with a couple of others to get complete control.</p>
<p></p>
<p>By Matthew Murphy spotted on Vulnwatch</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D169+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;t=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;title=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;title=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;title=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;title=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F05%2Fproof-of-concept-for-internet-explorer-modal-dialog-exploit%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

