Цитата в переводе не нуждается:
When you install TrendMicro Antivirus on Windows, by default a component called Password Manager is also installed and automatically launched on startup.
http://www.trendmicro.com/us/home/products/software/password-manager/index.html
This product is primarily written in JavaScript with node.js, and opens multiple HTTP RPC ports for handling API requests.
It took about 30 seconds to spot one that permits arbitrary command execution, openUrlInDefaultBrowser, which eventually maps to ShellExecute().
This means any website can launch arbitrary commands, like this:
x = new XMLHttpRequest() x.open(«GET», "https://localhost:49155/api/openUrlInDefaultBrowser?url=c:/windows/system32/c... true); try { x.send(); } catch (e) {};
Ты такой поставил Вин10 @ свистим, пердим, сливаем данные @ ставим антивирус @ безопасно-модно-молодежно %)