Prev | Current Page 365 | Next

Rich Cannings, Himanshu Dwivedi, Zane Lackey, and Alex Stamos

"Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions"

The control performs
the following actions:
??? Uses a Visual Basic script to access the user??™s local ?¬? le system and create a ?¬? le of
an attacker??™s choice.
??? Invokes the Shell.Explorer Class ID, which opens a web browser in control of
the attacker.
210 Hacking Exposed Web 2.0
The code for ActiveX.stream is as follows:


ActiveX.stream


ActiveX.stream



CLASSID="CLSID:8856F961-340A-11D0-A96B-00C04FD705A2">




To show how an attacker might abuse ActiveX controls for his own advantage, let??™s
walk through ActiveX.stream.
Make sure you install the ActiveX control on a lab machine and not on a corporate laptop or production
server. This control will download code that could be harmful to your system.


Pages:
353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377

Okna PCV Wrocław basketball.sport24x7.net projektowanie ogrodów łódź Wczasy nad morzem plac zabaw