OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
applicable exploit for winxp-sp2-uptodate Internet Explorer

From: Liu Die Yu (liudieyuumbrella.name)
Date: Tue Jan 11 2005 - 10:33:15 CST


patch will come in hours(at least i believe so).

many people(paul of greyhats and mike, sandblad of secunia and shreddersub7) already provided proof-of-concept remote-code-execution exploit for winxp-sp2-uptodate Internet Explorer.

the problem is: their code is simply not applicable in real attack. so i made this:
http://0daymon.org/monitor/injecthh-op-2/dir/injecthh_op_2-code_by_liudieyu
http://0daymon.org/monitor/injecthh-op-2/dir.zip