Re: [Full-disclosure] Firefox fun



Some of the reported crashes (IE 6, FF 1.5.0.5) could be the process
running out of memory; the current demonstration uses a huge block of
memory for reliability reasons. I should be able to tune the memory
allocation for the final exploit (to be included in the metasploit
framework). Thanks for all the feedback!

-HD

On Friday 28 July 2006 13:47, H D Moore wrote:
The demonstration exploit now works on Windows, Linux, and both
architectures of Mac OS X. A friend of mine reported that is also works
on the Camino browser:

http://browserfun.blogspot.com/2006/07/mobb-28-mozilla-navigator-object
.html

Enjoy,

-HD

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: [Full-disclosure] All you WMF haxxors are belong to...... Mr Moore
    ... the Framework to run out of memory. ... 'max size' we place on a protocol response, its never going to be small ... > Full-Disclosure - We believe in it. ... > Charter: http://lists.grok.org.uk/full-disclosure-charter.html ...
    (Full-Disclosure)
  • RE: [Full-Disclosure] Printer Buffer Security??
    ... Just because a printer has non-volatile memory in it doesn't mean they use ... > | looses it's buffer memory when unplugged. ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
    (Full-Disclosure)
  • Re: Comic Strip Index Retro - Philadelphia, 1981
    ... Recklessly refusing to invoke the Fifth Amendment, ... Charter Co. paper ... This list is from my memory. ...
    (rec.arts.comics.strips)
  • Re: [Full-Disclosure] Firefox 0.92 DoS via TinyBMP
    ... colour bitmap. ... That's going to take a lot of memory when there are ... Full-Disclosure - We believe in it. ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
    (Full-Disclosure)
  • Re: Potato clock
    ... Don't think that I have but my memory is not what it was, ... Think of Peach Melba. ... Please take time to read the Charter & FAQs for uk.education.staffroom: ...
    (uk.education.staffroom)