Chercher sur php.net


ground418 security
Chercher sur mysql



Voici la 178e page demandée aujourd'hui.
Img
Img2
Img3
Img4
Img6
Img7
Img8
Img9


Recherche


sur Internet
sur ground418




Alertes récentes
10-ForumCMS-JS
10-FlashSlideshowMaker-bufferOF
10-Canteen-fileInclude-SQLinject
10-getnnmdata-exec.txt
10-Sebo014-DoS
jaime mieux...

le php
l'asp
le perl
le html
le cafe noir


résultats
Exploits et Vulnérabilités logiciel sur ground418

Résumé / Abstract :

Un certain code Javascript fait planter Safari 4.0.4


Texte original (anglais) :

The following piece of javascript will crash Safari nicely when triggered using one of the methods described below. With my limited knowledge I am unable to tell if it's exploitable or not. I therefore turn it over to "the internet". (tested on Safari 4.0.4, Win XP Pro SP3)

============================

<script>
var data = "A";
while(data.length<0x40000){
data += data;
}
data2 = new Array();
for (x=0; x<4000; x++){
data2[x] = data+data;
}
</script>

============================

The crash is not immediate, but there are actually two ways to trigger it and I believe they are separate problems.

The following will cause Safari to crash with ?Access violation reading [00000000]?.

* Window->Activity

Whereas these will crash Safari with ?Access violation writing to [BBADBEEF]?

* Develop->Start Debugging Javascript
* Develop->Show Error Console (Unreliable)
* Develop->Show Web Inspector (Unreliable)
* (Right Click)->Inspect Element

I can?t seem to affect any registers in an advantageous way but I do see several pointers to x41 blocks on the stack. At least you could put shellcode in these and jump to them if you could control EIP. If anyone is able to do anything with this, please let me know.

Les avis les plus populaires de 2010
e107remote.txt
09-pyForum-backdoor
10-ForumCMS-JS
09-
06-alternC-095.txt
09-IPB-XSS
09-PhpShop-multi
09-jumi205
09-SMF-activeXSS
Statistiques pour
cet article :


AnnéeConsultations
2010289

Total289
partenaires




Hébergement

 
Rapide et sécuritaire
1.866.509.4313