From: methodman [methodman@GO.RO]
Sent: Thursday, June 01, 2000 4:33 PM
To: VULN-DEV@SECURITYFOCUS.COM
Subject: Re: Outlook/HTML "proggie"
well...
since everybody is so interested in what the SCR object is, i'm going to tell you...
it is an activex control with the classID: 06290BD5-48AA-11D2-8432-006008C3FBFC ,
it's name is actually SCRiptlet.typlib (that's why i gave it the id SCR). WSH has the classID
F935DC22-1CF0-11D0-ADB9-00C04FD58A0B and is called "Windows Scripting Host Shell Object",
(Wscript.SHell - therefore i gave it the id WSH).
about badblood... i didn't even hear about it until Thierry said it exists, same goes for the code written by Exxtreme.
about the source code... if you are reading this through outlook check "thisreallyworks.txt" on your desktop :)).
-- this only works if the security level is not set to "restriced sites zone"
 
 
 
[ methodman ]