WMF browser-ish exploit vectors

2005-12-30 Thread Evans, Arian
Here, let's make the rendering issue simple: Due to IE being so content help-happy there are a myriad of IE-friend file types (e.g.-.jpg) that one can simply rename a metafile to for purpose of web exploitation, and IE will pull out the wonderful hey; you're-not-a-jpeg-you're-a-something-else-that

Re: WMF browser-ish exploit vectors

2006-01-04 Thread Nick FitzGerald
Evans, Arian wrote: > Due to IE being so content help-happy there are a > myriad of IE-friend file types (e.g.-.jpg) that one > can simply rename a metafile to for purpose of web > exploitation, and IE will pull out the wonderful hey; > you're-not-a-jpeg-you're-a-something-else-that-I-can- > -auto

Re: WMF browser-ish exploit vectors

2006-01-05 Thread Dave Korn
Evans, Arian wrote in news:[EMAIL PROTECTED] > Here, let's make the rendering issue simple: > > Due to IE being so content help-happy there are a > myriad of IE-friend file types (e.g.-.jpg) that one > can simply rename a metafile to for purpose of web > exploitation, and IE will pull out the wond

RE: WMF browser-ish exploit vectors

2006-01-05 Thread James C Slora Jr
Dave Korn wrote > Have you tried giving it a mpg/avi/wma/wmv extension and getting > it to open in a (perhaps embedded) mediaplayer? That's liable to > work as well; mediaplayer is also vulnerable to the > choose-an-app-based-on-extension/app-loads-a-viewer-based-on-actual-content > desynchroni