当前位置:网站首页>Microsoft IE local file reading vulnerability
Microsoft IE local file reading vulnerability
2022-04-21 16:37:00 【Sword-heart】
Vulnerability Details
Disclosure status :
2010-08-02: Actively contact the manufacturer and wait for the manufacturer to claim , Details are not made public
2010-08-02: Manufacturers have taken the initiative to ignore vulnerabilities , The details are made public
A brief description :
Microsoft IE There are some problems when dealing with access to local files , Combining with Microsoft windows The feature may be able to read some local special files , There may be other uses .
Detailed instructions :
As a browser, it is inevitable to deal with the problem of cross domain resource access , Then some tags that must allow cross domain, such as iframe,script,style, These tags allow parsing of files in certain formats , If it conforms to javascript Syntax file , accord with css Syntax file , Once local, these files contain sensitive data , Cross domain reading is allowed , Microsoft throws an error when accessing local files ( Can be used to determine whether local files exist ), But the use of windows Features can bypass this limitation , By default c$ Oh ,win7+ie8 The test passed
<script src="\\127.0.0.1\c$\something.js"></script>
Vulnerability to prove :
Travel early security_id It is stored in a local file in a fixed location , adopt script You can reference this file , At the same time, combine some javascript You can get the security_id So as to carry out various operations remotely .
Repair plan :
Think about it , Anyway, loopholes are like IIS File parsing is the same , It has little effect on you
Copyright notice : Please quote source for reprint Kekkaishi @ Dark clouds
版权声明
本文为[Sword-heart]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204211632371083.html
边栏推荐
- What is ram running memory
- How where used list in SAP GUI is implemented
- 启动Redis的过程
- Apache安全配置
- Online dictionary website
- Infrastructure knowledge: DNS command: dig, host
- SIGIR 2022 | reinforcement learning recommendation system from the perspective of prompt
- Add release configuration in clion
- Mina中的Scan State
- Outsourcing student management system detailed architecture design document
猜你喜欢

2018-8-10-使用-Resharper-特性

Changan dark blue's first product can be pure electricity, extended range and hydrogen electricity, with an acceleration of 5.9s

Invalid bound statement (not found)问题解决
掌握自动化测试必要的几种技能?

排序课后练习题

MinGW Download

The console displays VM + number + file name to debug

C# 滑动验证码|拼图验证|SlideCaptcha

SIGIR 2022 | reinforcement learning recommendation system from the perspective of prompt

【面试普通人VS高手系列】能谈一下CAS机制吗?
随机推荐
目前5G SoC 芯片技术成熟吗?
Is hardware and software collaboration important?
SIGIR 2022 | reinforcement learning recommendation system from the perspective of prompt
微软IE本地文件读取漏洞
Use of Arthas tunnel
Summary of DOM operation elements
OJ每日一练——发放奖金
What are the technological innovations of Apple A13 Processor?
携程网主站XSS漏洞
Invalid bound statement (not found)问题解决
elmentUI表单中input 和select长度不一致问题
巴比特副总裁马千里:元宇宙时代NPC崛起,数字身份协议或成为入口级产品丨2022元宇宙云峰会
打卡:4.21 C语言篇 -(1)初识C语言 - (11)关键字register,#define定义的宏
Want to make a fortune by "leaking data"? What a punishment
网易的XSS
How where used list in SAP GUI is implemented
Historical evolution, application and security requirements of the Internet of things
程序设计天梯赛L3-28 森森旅游(想到multiset就算成功)
2018-8-10-使用-Resharper-特性
4.25 unlock openharmony technology day! The annual event is about to open!