Tuesday, April 05, 2005

Just posted on a VERY IMPORTANT update about Firefox

Just posted on a VERY IMPORTANT THREAD: Update about Firefox

Exclamation Just in time: SELF-TESTING posted Today 05:18 PM
(post #13)

SELF-TESTING

quote:
Like maybe...say....passwords?! eek


Just about time to post this, ric-o.

For you guys who want to test the script! (Take extreme precautions!).

I am curious for the source of the testing page facilitated for this vulnerability. I checked it (not being scriptkiddie or something), just plain curiousity, I extracted the most important part of the script just to find out what is really happening.

First, try the attached html (crash_JS_FF.html in zip file [crash_JS_FF.zip] --extract it first) and try it on a testing BoX (remember, testing BoX).

Here are the observations:

- Using Firefox, I run the HTML.
- Clicking the “Test Now - Left Click On This Link” each time reveals somewhat random data extracted from the memory. This is exciting to explore. I’ve come across this “LOAD_DOCUMENT_URI LOAD_RETARGETED_DOCUMENT_URI LOAD_REPLACE LOAD_INITIAL_DOCUMENT_URI LOAD_TARGETED - - userPass username password hostPort asciiSpec asciiHost”. Not yet scary huh!

Note that it crashes on my TEST BOX after clicking 3 times or more (never crashed lower than 3 clicks)… Randomly observe how many clicks you can possibly do before it crashes. I am still observing when would sensitive info like user and password could show up. Still not came across that severity. But one thing for sure, with the random exposure of memory content, too many sensitive information about your BoX and activities could be revealed. Whew. For those who want to try this (in a TEST BoX), please have your feedback on it. And just an added observation, check the task manager how it reacts every time you click. The Memory usage for some program changes in my BoX. *(XP Pro) ?

*
Need to add that in IE (latest), nothing happens except for showing the XXXXXXXXXXX... Not crashing. LoLz
*

Just to share some curiosity and observation. Remember, TAKE NECESSARY PRECAUTIONS BEFORE DOING THIS, BE SURE YOU KNOW WHAT TO DO!

Cheers!

Yo!


Attachment:

crash_js_ff.zip
This has been downloaded 3 time(s).
Who Downloaded This Attachment?

__________________
"Life without FREEDOM is no life at all". - William Wallace
MyhomE MyboX StealtH (loop n. see loop.)

Last edited by scratchONtheBOX on Today at 05:45 PM

*added

0 Comments:

Post a Comment

<< Home