BleepingComputer.com: Adodb.connection Proof Of Concept Vulnerability

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Adodb.connection Proof Of Concept Vulnerability

#1 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,518
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 28 October 2006 - 07:58 AM

Quote

...A recently discovered vulnerability in ADODB.connection has a proof of concept exploit. Microsoft has mentioned it in their blog. William believes this will be the 'drive by' threat vector of the next little while. This particular threat impact is remote code execution of choice.

The code creates new ActiveXObject('ADODB.Connection.2.7') and then executes a number of times. The PoC is a Denial of Service, but it is just a question of time until a working version with shellcode is out (if not already)...
isc.sans.org

MS Blog: ADODB.Connection POC Published
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users