Results 1 to 8 of 8

Thread: Explorer? ahiahiahiahiahi!

  1. #1
    Randolk's Avatar
    Join Date
    Oct 2003
    Location
    Eternia
    Posts
    35.505

    Default Explorer? ahiahiahiahiahi!

    Per quei 3-4 aspiranti suicidi che ancora utilizzano Explorer, testate il vostro brauser con questo POC:

    http://lcamtuf.coredump.cx/iedie.html

    Se crasha com'è probabile, vi sconsiglio *fortemente* di utilizzarlo nei prossimi giorni, almeno finchè M$ non butta fuori la pezza.
    Articolo originale di Zalewski:

    http://www.securityfocus.com/archive.../30/0/threaded
    Spoiler

  2. #2
    Lieutenant Commander San Vegeta's Avatar
    Join Date
    Oct 2003
    Location
    Bologna
    Posts
    12.154

    Default

    che figata
    I rubinetti a casa di Chuck Norris non perdono, vincono.

    In the beginning there was nothing...then Chuck Norris Roundhouse kicked that nothing in the face and said "Get a job". That is the story of the universe.

    Quote Originally Posted by Wolfo View Post
    Concordo e propongo ban temporanei per chi critica la topa , la topa non si critica , dal trombabile in su non si commenta in modo sgradevole.
    la tua ignoranza in materia e' raccapricciante
    -cit. Estrema, 2022

  3. #3
    Lieutenant Commander San Vegeta's Avatar
    Join Date
    Oct 2003
    Location
    Bologna
    Posts
    12.154

    Default

    non mi funziona il link con l'articolo, cmq è un sorgente html con un tag aperto e non chiuso, c'è lo stesso attributo onclick ripetuto svariate volte e poi un tag <p> in cui scrive Hello cruel world. Immagino che non isa gestito bene il parsing dei tag... chissà se ho ragione
    I rubinetti a casa di Chuck Norris non perdono, vincono.

    In the beginning there was nothing...then Chuck Norris Roundhouse kicked that nothing in the face and said "Get a job". That is the story of the universe.

    Quote Originally Posted by Wolfo View Post
    Concordo e propongo ban temporanei per chi critica la topa , la topa non si critica , dal trombabile in su non si commenta in modo sgradevole.
    la tua ignoranza in materia e' raccapricciante
    -cit. Estrema, 2022

  4. #4
    -=Mastro Pecoraro=- -=Rho=-'s Avatar
    Join Date
    Sep 2003
    Location
    Pecoronia
    Posts
    5.345

    Default

    Good morning,

    This might not come as a surprise, but there appears to be a *very*
    interesting and apparently very much exploitable overflow in Microsoft
    Internet Explorer (mshtml.dll).

    This vulnerability can be triggered by specifying more than a couple
    thousand script action handlers (such as onLoad, onMouseMove, etc) for any
    single HTML tag. Due to a programming error, MSIE will then attempt to
    write memory array out of bounds, at an offset corresponding to the ID of
    the script action handler multiplied by 4 (due to 32-bit address clipping,
    the result is a small positive integer).

    The list of IDs can be found on the Web, and is as follows (values in
    parentheses = resulting offsets):

    onhelp = 0x8001177d (+0x45df4)
    onclick = 0x80011778 (+0x45de0)
    ondblclick = 0x80011779 (+0x45de4)
    onkeyup = 0x80011776 (+0x45dd8)
    onkeydown = 0x80011775 (+0x45dd4)
    onkeypress = 0x80011777 (+0x45ddc)
    onmouseup = 0x80011773 (+0x45dcc)
    onmousedown = 0x80011772 (+0x45dc8)
    onmousemove = 0x80011774 (+0x45dd0)
    onmouseout = 0x80011771 (+0x45dc4)
    onmouseover = 0x80011770 (+0x45dc0)
    onreadystatechange = 0x80011789 (+0x45e24)
    onafterupdate = 0x80011786 (+0x45e18)
    onrowexit = 0x80011782 (+0x45e08)
    onrowenter = 0x80011783 (+0x45e0c)
    ondragstart = 0x80011793 (+0x45e4c)
    onselectstart = 0x80011795 (+0x45e54)

    What happens next depends on the structure of the page in which the
    malicious tag is embedded, as well as previously visited page and
    previously initialized extensions (all these factors can be controlled by
    the attacker).

    When the offending page contains no additional elements, and the user is
    not redirected from elsewhere, the browser will typically crash
    immediately, because there is no allocated memory at the resulting offset.
    In all other cases, crashes will typically occur later, due to attempted
    use of unrelated but corrupted in-memory buffers -for example, when the
    user attempts to leave or reload the page. Another good example is coming
    from a page that contains Macromedia Flash - this usually causes the Flash
    plugin itself to choke on corrupted memory on cleanup.

    For non-believers, there's a short but fiery demonstration page available
    at http://lcamtuf.coredump.cx/iedie.html (yes, it will probably crash your
    browser).

    Tested on MSIE 6.0.2900.2180.xpsp2.040806-1825 on Windows XP SP2. As far
    as I can tell, other browser makes (Firefox, Opera) are not susceptible to
    this attack.

    I eagerly await due reprimend from Microsoft for not disclosing this
    vulnerability in a manner that benefits them most, not passing start, not
    collecting $200 (from iDefense?).

    Regards,
    /mz
    http://lcamtuf.coredump.cx/silence/
    Questo l'articolo del link
    Quote Originally Posted by Thor View Post
    sto stappando una delle migliori bottiglie che ho in casa
    ora siete coglioni al quadrato
    Quote Originally Posted by Nazgul Tirith View Post
    MA CHE PORCO DIO AVETE 6 ANNI?

  5. #5
    Lieutenant Commander
    Join Date
    Jan 2005
    Location
    Toscana
    Posts
    10.507

    Default

    IE crasha davvero!
    ...
    Now Working..



  6. #6
    Warrant Officer Andreazakk's Avatar
    Join Date
    Feb 2004
    Location
    Napoli
    Posts
    2.934

    Default

    Perchè a me non crasha?
    Once upon a time..
    Sedrimyr RullaAbbastanza Ranger on Lancelot
    Elvetico Mentalist on Lancelot
    Jebe Diah Warden on Lancelot <-- fratello
    Mimmo IlBucchinaro Healer on Mlf
    Sedrimyr Hunter on Mlf
    Sedrimyr Hunter on Ceridwen[ITA]
    Mirea Reaver on Argain[ITA]
    Sedrimyr deleted Mercenary on Vortigern[ITA]
    etc. etc. etc.

  7. #7
    Petty Officer 2nd Class Manshoon's Avatar
    Join Date
    May 2004
    Location
    Mondolfo PU
    Posts
    709

    Default

    Quote Originally Posted by Andreazakk
    Perchè a me non crasha?
    A me crasha

  8. #8
    Warrant Officer Taro Swarosky's Avatar
    Join Date
    Apr 2004
    Location
    Abruzzo, Teramo
    Posts
    3.357

    Default

    da mettere in firma direi
    DAoC RvR was great not for the rewards, but for the playerbase that played it because they wanted to RvR. The tragedy of WAR RvR is that it's being played largely by a bunch of WoW-age crybabies that don't want to RvR for fun, but consider it a grind required for rewards.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
[Output: 72.26 Kb. compressed to 61.71 Kb. by saving 10.56 Kb. (14.61%)]