Re: Internet Explorer 6 CSS "expression" Denial of Service Exploit (P.o.C.)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 12/6/06, José Carlos Nieto Jarquín <xiam.core@xxxxxxxxx> wrote:> Note:> I'm sorry, two of the the exploits in the prior e-mail were incomplete.>> This is just another couple of proof of concept exploits for this> well-known browser. The third one is a lame combination of both.>> Tested under Windows XP SP2, MSIE 6.0.2900.2180

Also confirmed working on Windows Server 2003 R2 (Build 3790) withInternet Explorer 7.0.5730.11
1st exploit was working fine putting iexplore.exe at 100% CPU. Itcomplained about "IE restricting this web page from running scripts"(probably because of enabled Internet Explorer Enhanced SecurityConfiguration), but if you click "allow this website to run this"(which is enabled by default if above mentioned IE ESC is not present)it works.
2nd and 3rd were not exactly working, (also because of IE ESC) becauseafter clicking allow after several windows it was asking again, butshould work on WinXP and IE7.


-- Andrius Paurys$h@MAN
andrius.paurys@xxxxxxxxxxxxx: +37067449273ICQ: 279424019MSN: andrius.paurys@xxxxxxxxxxxxx://shaman.tinkle.lt/
I'm Lithuanian, what's _your_ excuse?Sėdi programeris nevalgęs ir nieko...

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux