[태그:] 취약점

웹페이지에 삽입되는 악성코드가 이용하는 취약점 리스트

MS Internet Explorer 7 Video ActiveX Remote Buffer Overflow Exploit (MS09-032) CLSID : 0955AC62-BF2E-4CBA-A2B9-A63F772D46CF http://www.microsoft.com/korea/technet/security/bulletin/MS06-014.mspx Internet Explorer Uninitialized Memory Corruption Vulnerability (MS09-002) CLSID : AE24FDAE-03C6-11D1-8B76-0080C744F389 http://www.microsoft.com/korea/technet/security/bulletin/MS09-002.mspx Internet Explorer (MDAC) Remote Code Execution Exploit (MS06-014) CLSID : BD96C556-65A3-11D0-983A-00C04FC29E36 http://www.microsoft.com/korea/technet/security/bulletin/MS06-014.mspx Microsoft Office Web Components (Spreadsheet) ActiveX BOF (MS09-043) http://www.microsoft.com/korea/technet/security/bulletin/ms09-043.mspx http://ij**ar.cn/x2/xx.html http://ij**ar.cn/x2/Td14.htm – MS06-014 http://ij**ar.cn/x2/14.js http://d.gd**w.com/xx/x2.css http://ij**ar.cn/x2/15.js http://ij**ar.cn/x2/17.js …

Microsoft IIS 5.0/6.0 FTP Server Remote Stack Overflow Exploit (win2k)

8월 31일자로 milw0rm 사이트에 제로데이가 올라왔습니다. 윈도우 FTP 서버 취약점인데 Remote라 심각성이 클것으로 보이네요. http://www.offensive-security.com/videos/microsoft-ftp-server-remote-exploit/msftp.html # IIS 5.0 FTPd / Remote r00t exploit # Win2k SP4 targets # bug found & exploited by Kingcope, kcope2<at>googlemail.com # Affects IIS6 with stack cookie protection # August 2009 – KEEP THIS 0DAY PRIV8 use IO::Socket; $|=1; #metasploit shellcode, …