[Full-disclosure] More URI Handling Vulnerabilites (FireFox Remote Command Execution)



Internet Explorer has received a lot of attention lately for the way
it handles requests for external URIs.... Nate and I have warned that
IE isn't the only browser with URI handling issues....

I've posted a PoC for remote command execution in Firefox (2.0.0.5),
Netscape Navigator 9, and mozilla at:
http://xs-sniper.com/blog/2007/07/24/remote-command-execution-in-firefox-2005/

These specific examples are built for WinXP SP2 WITH NO OTHER EXTERNAL
EMAIL programs installed. Users with Outlook, notes, or other
external mail programs installed may have had their URI handlers
modified by the external program.

Take some improperly registered URIs combined with a lack of
sanitation by the browser and we've got problems.... its time to take
another look at the URIs on your machine...

--
Billy (BK) Rios
http://www.xs-sniper.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: urlencode and $_GET
    ... >again, it's the browser the one who 'encodes' the url, not you. ... escaping malformed URI reference ... An URI contains non-authorized characters. ... RFC2396 - Uniform Resource Identifiers: ...
    (comp.lang.php)
  • Re: redirect with Anchor Tag in IE
    ... I can't reproduce your problem with my Internet Explorer web ... browser (version 6.0.2600.0000IC, Windows 98). ... part of the URI in a Location header. ...
    (comp.lang.php)
  • Re: Forcing retrieval of a fresh copy of a file with a link
    ... to serve a fresh copy of a file or B) the browser to "refresh" the ... HTTP is "RESTful", which means that you can't do this (as ... There's a link on a page which tells you the URI by which to ... send headers that indicate to the browser it can continue to use the ...
    (comp.infosystems.www.authoring.html)
  • Re: PicForth 1.0 is released
    ... > Rune> I can't access the homepage error 406 not acceptable ... > It means that your browser didn't accept any of the possible versions ... > URI: picforth.html.fr.gz ...
    (comp.arch.embedded)
  • Re: open-uri bug
    ... On Feb 26, 12:20 pm, Rob Biedenharn ... This is a bit unfortunate, ... tool which has to handle URIs the same way the browser does. ... functionality of the browser fetch using the URI module. ...
    (comp.lang.ruby)