|
 |
您现在的位置: 红色黑客联盟 >> 教程 >> 黑客技术 >> 漏洞利用 >> 正文 |
| Google Chrome Browser 0.2.149.27 malicious link DoS Vulnerability |
|
|
|
| 文章录入:7747.Net 责任编辑:7747.Net |
|
|
【字体:小 大】 |
|
Software: Google Chrome Browser 0.2.149.27 Tested: Windows XP Professional SP3
Result: Google Chrome Crashes with All Tabs
Problem: An issue exists in how chrome behaves with undefined-handlers in chrome.dll version 0.2.149.27. A crash can result without user interaction. When a user is made to visit a malicious link, which has an undefined handler followed by a 'special' character, the chrome crashes with a Google Chrome message window "Whoa! Google Chrome has crashed. Restart now?". It lies in dealing with the POP EBP instruction when pointed out by the EIP register at 0x01002FF4.
Proof of Concept: http://evilfingers.com/advisory/google_chrome_poc.php
Credit: Rishi Narang (psy.echo) www.greyhat.in www.evilfingers.com ---------------------------------------------------
PoC Working/Exploit: Click for a demo <a href="EVIL:%">HERE</a>
# milw0rm.com [2008-09-03]
|
| |
| 您对本文章有什么意见或着疑问吗?请到论坛讨论您的关注和建议是我们前行的参考和动力 |
|
|
| |
上一篇文章: PhpBazar adid SQL注入漏洞
下一篇文章: 没有了 |
| 【发表评论】【加入收藏】【告诉好友】【打印此文】【关闭窗口】 |