Prev | Current Page 365 | Next

Rich Cannings, Himanshu Dwivedi, Zane Lackey, and Alex Stamos

"Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions"

The control performs
the following actions:
??? Uses a Visual Basic script to access the user??™s local ?¬? le system and create a ?¬? le of
an attacker??™s choice.
??? Invokes the Shell.Explorer Class ID, which opens a web browser in control of
the attacker.
210 Hacking Exposed Web 2.0
The code for ActiveX.stream is as follows:


ActiveX.stream


ActiveX.stream



CLASSID="CLSID:8856F961-340A-11D0-A96B-00C04FD705A2">




To show how an attacker might abuse ActiveX controls for his own advantage, let??™s
walk through ActiveX.stream.
Make sure you install the ActiveX control on a lab machine and not on a corporate laptop or production
server. This control will download code that could be harmful to your system.


Pages:
353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377

news news news news news