|
|
|
Safari 3.2.1 for windows SafariURL protocol Handler abusse null Deference |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Safari 3.2.1 for windows SafariURL protocol Handler abusse null Deference Par Lostmon BloggerLe [2010-02-07] à 19:10:25
Présentation : Safari 3.2.1 for windows safariUrl protocol Handler abusse null Deference Vendor http www.apple.com original advisore http lostmon.blogspot.com 2009 01 safari-321-for-windows-safariurl.html vendor notify YES Exploit available Private This article is a second part of http lostmon.blogspot.com 2009 01 safari-for-windows-321-remote-http-uri.html Safari for windows in prone vulnerable to a null pointer deference in protocols handlers http, ftp and SafariURL. The issue is triggered when a user in click a specially crafted link with malformed uri that causess a NULL pointer derefence safari, and will result in loss of availability for the browser. In the case of SafariURL is very curious, because we can compose a malformed url like SafariIRL .. or SafariURL http .. or ftp .. and wen try to open it whith safari,safari opens a new windows , and wen we try to close this new one,clicking in the 'X' the window is closed, but it reopens again ... sO why it opens again in a infinite loop Take a look of posible source code of the fucnction. in any place of the code before using a pointer, it check that it is not equal to NULL Part of code affected CFURLRef safariURL nil OSStatus err LSFindApplicationForInfo kLSUnknownCreator, CFSTR com.apple.Safari , nil, nil, if err noErr displayErrorAndQuit Unable to locate Safari , Nightly builds of WebKit require Safari to run. Please check that it is available and then try again. NSBundle safariBundle NSBundle bundleWithPath NSURL safariURL path CFRelease safariURL return safariBundle Simple PoC usr bin perl Safari_httpDoSPoc.pl Safari for Windows 3.2.1 Remote http uri handler DoS Lostmon Lostmon gmail.com http lostmon.blogspot.com archivo ARGV 0 if defined archivo print Uso 0 n cabecera Safari 3.2.1 for windows Browser Die PoC By Lostmon . n codigo Safari 3.2.1 for windows Browser Die PoC By Lostmon lostmon gmail.com http lostmon.blogspot.com This PoC is a malformed http ,safariurl and ftp URI, this causes that safari for windows turn inestable and unresponsive. Click THIS link. Safari Die or this other Safari Die Safari Die or this other Safari Die piepag datos cabecera . codigo . piepag open FILE, '' . archivo print FILE datos close FILE exit I don t know if it has remote code execution, or other i make SEVERAL test and only can cause a DoS , i don t know if we can change NSBundle... this issue with SafariURL can exploit across other browsers. wen open the link with other browsers it executes safari.exe -url link Thnx To estrella to be my ligth Thnx to all Lostmon Team. -- atentamente Lostmon lostmon gmail.com Web-Blog http lostmon.blogspot.com Google group http groups.google.com group lostmon new -- La curiosidad es lo que hace mover la mente....Lostmon lostmon gmail.com Web-Blog http lostmon.blogspot.com Google group http groups.google.com group lostmon new -- La curiosidad es lo que hace mover la mente....
Les mots clés de la revue de presse pour cet article : safari windows protocol Les videos sur SecuObs pour les mots clés : windows protocol Les mots clés pour les articles publiés sur SecuObs : windows protocol Les éléments de la revue Twitter pour les mots clé : safari windows protocol
Les derniers articles du site "Lostmon Blogger" :
- Internet explorer 7 8 URL Validation Vulnerability - Safari for Windows 3.2.1 Remote http URI handler DoS - Safari 3.2.1 for windows SafariURL protocol Handler abusse null Deference - Entidades bancarias españolas ante el phishing II - IE8 beta RC1 res ieframe.dll acr_error.htm Spoff - Comtrend HG536 vulnerabilities - Safari 4 Automatic explorer.exe launch - Caixa Sabadell Parchea sus dominios web - Caja Granada ha Parcheado Su web - Comtrend HG536 poligon firmware tftp vuln
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, microsoft, réseau, attaque, outil, vulnérabilité, audit, système, virus, internet, données, présentation, metasploit, linux, bluetooth, protocol, vista, scanner, réseaux, shell, engineering, rootkit, paquet, conférence, trames, wishmaster, téléphone, source, sysun, noyau, mobile, https, mémoire, rapport, botnet, téléphones, libre, reverse, navigateur, patch, snort, scapy, intel |
| Mini-Tagwall de l'annuaire video : | | | | vmware, security, virus, biometric, windows, lockpicking, password, botnet, metasploit, tutorial, attack, crypt, linux, network, iphone, server, exploit, wimax, conficker, virtu, virtual, engineering, cisco, reverse, shmoocon, wireshark, ettercap, hacker, firewall, internet, knoppix, rootkit, arduino, wireless, source, conference, backtrack, openbsd, brucon, systm, overflow, openssh, access, buffer, remote |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|