IE Object Data Tag exploit v1.31

Vulnerability exploited: CAN-2003-0532 - BID-8456

Category: Exploits/Client Side

This module will listen HTTP requests from vulnerable clients and install a Level0 agent on them.
This module runs a web server waiting for vulnerable clients (Internet Explorer) to connect to it. When the client connects, it will try to install a Level0 agent by sending a specially crafted HTML page which exploits the Internet Explorer Object Data Tag vulnerability.You can force vulnerable clients to connect to the web server automatically by using this module to send them an specially designed e-mail to exploit this vulnerability if the client uses Outlook Express to read their mails.In order to successfully exploit this vulnerability, the outlook express option "Internet zone (Less secure, but more functional)" in "Options->SECURITY" must be enabled. By default this option comes disabled, if the victim receives the exploit's mail with this option disabled, he will see the following warning: "Your current security settings prohibit running ActiveX controls on this page. As a result, the page may not display correctly.".

Supported Systems:
    Windows 2000 Professional - sp0 (i386)
    Windows 2000 Professional - sp1 (i386)
    Windows 2000 Professional - sp3 (i386)
    Windows 2000 Professional - sp4 (i386)
    Windows 2000 Server - sp0 (i386)
    Windows 2000 Server - sp1 (i386)
    Windows 2000 Server - sp4 (i386)
    Windows 2000 Advanced Server - sp0 (i386)
    Windows 2000 Advanced Server - sp1 (i386)
    Windows XP Professional - sp1 (i386)
    Windows 2000 Professional - sp1 (i386) - IE 5.0.3103.1000
    Windows 2000 Professional - sp3 (i386) - IE 6.0.2800.1106
    Windows 2000 Professional - sp4 (i386) - IE 6.0.2800.1106
    Windows 2000 Server - sp4 (i386) - IE 6.0.2600.000
    Windows 2000 Advanced Server - sp0 (i386) - IE 5.00.2920.0000
    Windows 2000 Advanced Server - sp1 (i386) - IE 5.00.3103.1000
    Windows XP Professional - sp1 (i386) - IE 6.0.2800.1106


This module is included in the latest version of CORE IMPACT, the first automated comprehensive penetration testing product for accurately identifying information security risks. Click here to learn more about the product.