functional security
Showing 1 - 1 of 1 RSS Feed

Files

mobb.tgz
Posted Aug 3, 2006
Site browserfun.blogspot.com

Exploit for Mozilla Firefox versions 1.5.0.4 and below. The demonstration exploit below will attempt to launch "calc.exe" on Windows systems, execute "touch /tmp/METASPLOIT" on Linux systems, and bind a command shell to port 4444 for Mac OS X Intel and PowerPC systems. An anonymous researcher for TippingPoint and the Zero Day Initiative showed that when used in a web page Java would reference properties of the window.navigator object as it started up. If the page replaced the navigator object before starting Java then the browser would crash in a way that could be exploited to run native code supplied by the attacker.

tags | exploit, java, web, shell
systems | linux, windows, apple, osx
advisories | CVE-2006-3677
MD5 | 99310b4fff62cfdeb795aeed9747822c
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close