Collection of working (live) browser exploits (malware)

From Malware Guru

Revision as of 05:01, 4 February 2009 by Crane Ku (Talk | contribs)
(diff) ←Older revision | Current revision (diff) | Newer revision→ (diff)
Jump to: navigation, search

Below is a list of WORKING, LIVE malware that we have collected for your experiment.

 Browser Security Test. You can use them for your study purposes, for testing your anti-virus, IDS, IPS, ... security solutions.
 Or for evaluating your enterprise malware solutions.

You're very welcome to submit a malware to us; we'll host it here if it indeed works. Please send your submission to: mailto:submitmalware@malwareguru.org


LIVE Malware Code List (Browser Security Test):

Exploit NameExploitable environmentCVE NO.Exploit availablePopularlyFile droppedActions after successful exploitation
MS05-052 IE (COM Object-Msdds.dll)CAN-2005-2127Not yet***--Expliot test
MS06-014 IE+MDACCVE-2006-0003Yes*****(temp)\svchost.exe"Found this vulnerability." message
MS06-042 IE (Long URL)CVE-2006-3869
CVE-2006-3873
Yes***(IE-temp)\test.avi
(temp)\g0ld.com
"Found this vulnerability." message
MS06-055 IE (VML)CVE-2006-4868Not yet**--Expliot test
MS06-067 IE (DirectAnimation ActiveX)CVE-2006-4777Yes**(SystemRoot)\system32\a.exe
(Temp)\Temp~\Cont~\\test.avi
"Found this vulnerability." message
MS07-004 IE (VML), Replace MS06-055CVE-2007-0024Yes*****(SystemRoot)\system32\~.exe
(IE-temp)\test.avi
"Found this vulnerability." message
MS07-016 IE (COM Objects)CVE-2007-0219
CVE-2006-4697
Not yet**--Expliot test
MS07-017 IE (Animated Cursor Handling)CVE-2007-0038Not yet**--Expliot test
MS07-033 IE (Language Pack Installation)CVE-2007-3027Not yet**--Expliot test
MS07-055 IE (Kodak Image Viewer)CVE-2007-2217Not yet**--Expliot test
MS08-011 IE+Office Words (File Converter)CVE-2007-0216
CVE-2008-0105
CVE-2008-0108
Not yet**--Expliot test
MS08-041 IE+Snapshot Viewer for AccessCVE-2008-2463Yes***c:\SnapShock.exeCreate File=> "c:\SnapShock.exe"
MS08-078 IE XML Heap Corruption exploitCVE-2008-4844Yes*****launches calculatorlaunches calculator
Plugin-AdobeFlash IE+Adobe Flash PlayerCVE-2007-0071Yes*****(IE-temp)\test.avi
(temp)\orz.exe
"Found this vulnerability." message
Plugin-BEWS IE+Symantec Backup Exec for Windows Server (BEWS)CVE-2007-6016
CVE-2007-6017
Not yet*--Expliot test
Plugin-LZ IE+LZ (Ourgame GLWorld, aka Lianzong Game)CVE-2008-0647Not yet**--Expliot test
Plugin-QvodPlayer IE+QvodPlayerNo CVE NO.Not yet*--Expliot test
Plugin-RealPlayer11 IE+Real Player 11CVE-2008-1309Yes*****c:\U.exe"Found this vulnerability." message
Plugin-StormII IE+Baofeng StormIICVE-2007-4816
CVE-2007-4943
Not yet*--Expliot test
Plugin-Thunder IE+ThunderCVE-2007-6144Not yet**--Expliot test
Video WebSite by PhishingSpoofingYes****Download FileRun and "Found this vulnerability." message
Video ActiveX by Phishing+ScriptSpoofingYes*****Download FileRun and "Found this vulnerability." message
Clickjacking Firefox 3.0.5, Chrome 1.0.154.43, Safari 3.2.1,IE 7.0.6001ClickjackingYes**ClickjackingYou will see phishing URL