[Full-Disclosure] IE Object Type Overflow Exploit

ash at felinemenace.org ash at felinemenace.org
Wed Jul 9 13:23:16 BST 2003


                     _,'|             _.-''``-...___..--';)
                     /_ \'.      __..-' ,      ,--...--'''
                    <\    .`--'''       `     /'
                    `-';'               ;   ; ;
               __...--''     ___...--_..'  .;.'
           fL (,__....----'''       (,..--''  felinemenace.org

Attached is an exploit for the Internet Explorer Object type  overflow found
by eEye.

This exploit uses more than 56 bytes for payload unlike the only other publicly
released exploit i could find by Sir Alumni.

More details can be found within the archive.
Please read the text file before running this exploit, keep in mind it does
download a trojan.

-FelineMenace

-------------- next part --------------
A non-text attachment was scrubbed...
Name: fm-IE.tar
Type: application/x-tar
Size: 10240 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20030709/f2427791/attachment.tar 


Full-Disclosure is hosted and sponsored by Secunia.