accept no compromises
Showing 1 - 8 of 8 RSS Feed

Files from Michael Krax

Email addressmikx at mikx.de
First Active2004-12-31
Last Active2006-01-26
fireclicking.txt
Posted Jan 26, 2006
Authored by Michael Krax | Site mikx.de

Using custom Microsoft Agent characters it is possible to cover any kind of windows, including security or download dialogs. This is an expected feature of the Microsoft Agent control. Because custom characters are fully scriptable, can have any kind of shape and are downloaded automatically, this can be used as a flexible tool to cover and/or spoof any kind of window and lure the user to execute arbitrary code by performing one or two clicks (depending on security zone configuration and Windows version).

tags | advisory, arbitrary, spoof
systems | windows
MD5 | 64aab85262376be4b710a7ace4d6f5f4
mfsa2005-47exploit.txt
Posted Jul 15, 2005
Authored by Michael Krax

Mozilla Firefox versions 1.0.4 and below 'Set As Wallpaper' code execution exploit.

tags | exploit, code execution
MD5 | 4edb4b62ae413afc0a51e8a7fc4eb985
firefox101.txt
Posted Mar 25, 2005
Authored by Michael Krax | Site mikx.de

Even though Firefox 1.0.1 patched one of the key bugs behind the firescrolling exploit (the ability of plugins to load chrome files in a hidden frame) the ability to hijack a drag and drop operation and open a privileged xul file is still available.

tags | advisory
MD5 | 18769e0ea4aec6844830c631a886e81e
Fireflashing.txt
Posted Feb 23, 2005
Authored by Michael Krax | Site mikx.de

Using plugins like Flash and the -moz-opacity filter, it is possible to display the about:config site in a hidden frame or a new window in Firefox 1.0 and Mozilla 1.7.5.

tags | advisory
advisories | CVE-2005-0232
MD5 | 1a888919694e733f676b439ed3dc0482
Firetabbing.txt
Posted Feb 23, 2005
Authored by Michael Krax | Site mikx.de

The Javascript security manager can be bypassed when a link is dropped to a tab in Firefox 1.0 and Mozilla 1.7.5.

tags | advisory, javascript
advisories | CVE-2005-0231
MD5 | e22cb9d98539910ade56614bdcb29ce3
Firedragging.txt
Posted Feb 23, 2005
Authored by Michael Krax | Site mikx.de

Firefox built-in protection against allowing dragged non-image files can be bypassed when an executable is passed with a content-type of image/gif. Tested with Firefox 1.0 and Mozilla 1.7.5.

tags | advisory
advisories | CVE-2005-0230
MD5 | 0cf3d7f3f08982e705c77f7fa51bf859
javaSpoof.txt
Posted Jan 12, 2005
Authored by Michael Krax | Site mikx.de

Using javascript, is it still possible to spoof the content of security and download dialogs by covering them with a pop up window. This flaw has gone unpatched for 3 months. Tested with Firefox 1.0, Mozilla 1.7.5 and Netscape 7.1 on Windows XP SP2.

tags | advisory, spoof, javascript
systems | windows, xp
MD5 | 34ff792dcfb1b2647aeab4d180213bb9
xssEverywhere.txt
Posted Dec 31, 2004
Authored by Michael Krax | Site mikx.de

A series of tests were performed to find Cross-Site Scripting (XSS) vulnerabilities. It quickly turned out that the majority of all major websites suffer from some kind of XSS flaw. This is a disclosure of 175 vulnerabilities at once.

tags | advisory, vulnerability, xss
MD5 | 003710494b7d82e6fcf4539f771db499
Page 1 of 1
Back1Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close