Microsoft says VBScript will be ripped from Windows in a future release
theregister.com
theregister.com
> "VBScript is being deprecated," Microsoft said. "In future releases of Windows, VBScript will be available as a feature on demand before its removal from the operating system."
This sounds like the opposite of "ripped" to me. Maybe "slowly withdrawn" might be more accurate.
"Ripped" implies (to me) a sudden and traumatic removal, without care for collateral damage that might be caused.
https://learn.microsoft.com/en-us/windows/whats-new/deprecat...
Payload: change a users signature to the program and hide the code on the edit page
Vectors:
- VScript - submit a request with the users cookies on IE (also defeats client-side CSRF tokens)
- Phispher - use javascript to show a phisphing page for the login screen as the signature code runs (works cross-browser but requires interaction.)
- PHP - collect forum logins and send requests to update signatures with the program
Results: I ended up spreading to most signatures in the forum, undetected. Ended up gaining access to all the forum admin users. From there is was easy to get a shell on the forum because there were theme uploads via the admin page. Called a reverse shell via perl -> nc with the www-data user and then privilege escalation with a local exploit to get root.
... but VBScript was still pivotal to spreading the code because IE was very wide-spread back then (and very, very vulnerable.) Good times / 10.
Do you mean phishing? I searched for "Phispher" thinking it might be a particular tool or something, but nothing turned up.
It was part of the OLE dream that users would have lots of small scripts automating their component-oriented workflows. What we got instead was cargo-cult coding and innumerable vulnerabilities because, to borrow a phrase from the IoT folks, the 'S' in COM/OLE stands for security.
There's no scripting MS Agents like Peedy and Bonzai Buddy from VBScript, but there are now a bunch of W3C-standardized APIs with varying levels of browser implementations catalogued at MDN and caniuse; WebSockets, WebRTC, WebUSB, WebBluetooth, WebGPU, WebNN, File System Access API: https://developer.mozilla.org/en-US/docs/Web/API/File_System...
From "Manifest V3, webRequest, and ad blockers" (2022) https://news.ycombinator.com/item?id=32953286 :
> What are some ideas for UI Visual Affordances to solve for bad UX due to slow browser tabs and extensions?
> - [ ] UBY: Browsers: Strobe the tab or extension button when it's beyond (configurable) resource usage thresholds
> - [ ] UBY: Browsers: Vary the {color, size, fill} of the tabs according to their relative resource utilization
> - [ ] ENH,SEC: Browsers: specify per-tab/per-domain resource quotas: CPU, RAM, Disk, [GPU, TPU, QPU] (Linux: cgroups,)
MS had the technology which used HTML for GUI: https://en.wikipedia.org/wiki/HTML_Application
Interestingly, it arrived in IE5 in 1999, almost 15 years before the very first version of Electron.
Examples include Unicode in NT 3.5, asynchronous I/O in NT 4, multi-CPU support in Win2k (become mainstream after hyperthreading and especially multicore CPUs), 3D GPU for desktop compositor in Vista (people universally hated the hardware requirement, but over time we got pretty fast 3D GPUs even inside low-end processors).
Sadly, it seems they stopped implementing awesome new stuff after Windows 7.
I'll give you an example: most hp printer setup crap uses mshta which if I remember right uses vbs code (could be jscript too). I assume since the windows script host supports both, this would affect jscript as well.
Later in my sysadmin life, I wrote massive logon scripts, printer deployment tools, computer auditing scripts, and much more with VBscript. It was a surprisingly capable scripting language. Later we learned how to add a nice GUI to the scripts using HTA which added an HTML front end using Internet Explorer.
The article makes very little mention of server-side use, just “Windows client” other than one quote.
Classic ASP is included with Windows Server 2022 so IIRC by the standard rules MS follows for server products it won't be fully deprecated there until some time in 2031, and that will include VBScript and JScript.
My only hope is that some BigCOs scream loud enough about MS breaking all their old stuff.
Excel macros are written in this by fortunate decisions in the article below, not sure if the windows cscript and wscript tools that execute vbs have dependency ties to excel https://www.joelonsoftware.com/2006/06/16/my-first-billg-rev... like outlook does to the word editor dlls.
Anything that can be virtualized should be virtualized.
I doubt if they'll ever be able to remove VBA. Way too much legacy code... the customers would mutiny.
I seem to recall a couple of other pesky nuances.
One thing I thought was a win decades ago in the ASP/pre-jQuery days was being able to tell where the code would execute based upon language.vVBSsript on the server; JS in the browser.
JS seems like an out-of-body experience as it is.