Welcome to TheBUGS - Security related portal. Search crack, serial number, keygen, patch, activation unlock code  - MSIE (mshtml.dll) OBJECT tag vulnerability
Press CTRL-D to bookmark us
Cracks, serial number, activation, unlock code, nocd
Welcome GuestLogin / Register / Members
Merge or split your pdf files ONLINE and FREE
Bookmark us | Set As Homepage | Advertising | Feedback | Recomend us | Link us | Your comments | Gallery | Terms
Security News | Security Library | Forums | Top Sites | Direct Downloads | Cracks / SN | Links | Books | XXX Area
TORRENTS -
 Network
 Top sites
 Direct Download Links
 Password Generator
 Cheats
 HackZone.RU - HACK & CRACK & ВЗЛОМ

 
 Forums
 Best Sites
1. Astalavista.net ...
2. FULL VERSION DOW...
3. CRACKZ & SER...
4. [ KEYGENS ] [ CR...
5. CrackPortal
6. 120000 Cracks &a...
7. BestCracks.net
8. ******** X-ACCES...
9. KEYGEN.ru :: Rus...
10. CrackSpider.net

 Full list
 Your site here
 
 Sponsor
 Partners

ProTorrent.com

msCracks.com

CrackSpider.NET



AllSeek

Best Cracks

HotSoft.us

Your link here
 


You are welcome to post comments and suggestions

Copyright 2001-2008 by Freeman
Search in

PROTORRENT.COM - Ultimate bittorrent database


> TOP10 SECURITY SITES <
Astalavista.net - Securit...
MOBILE-REVIEW.WS :: News ...
Curse-X.COM
NET WANDERER
hcR Security Team
13337
SecureDeath[d0t]com
Your site here
Your site here
Your site here
>> Your site here <<

Top Submit newsSubscribe
Access Control // Auditing // Communication // Computer Crime // Confidentiality // Cryptography // Digital Imaging // Exploit // Gadgets // Hack // Hardware // Incidents // Internet // Intrusion Detection // Linux // Malicious Code // Microsoft Windows // Mobile // Other // PDA // Phreaking // Privacy // Software Updates // Virus // Vulnerability //


Previous articleBack to news listNext article
 
 Sponsored links

Want to become one of our authors and see your work published on TheBUGS ?
 
 MSIE (mshtml.dll) OBJECT tag vulnerability
Categorie: Vulnerability
Posted: 2006-06-13 by DiMan
Views: 17540
Source: Click here
 
Current Rating: Not rated
Poor Best
 Details
Perhaps not surprisingly, there appears to be a vulnerability in how
Microsoft Internet Explorer handles (or fails to handle) certain
combinations of nested OBJECT tags. This was tested with MSIE
6.0.2900.2180.xpsp.040806-1825 and mshtml.dll 6.00.2900.2873
xpsp_sp2_gdr.060322-1613.

At first sight, this vulnerability may offer a remote compromise vector,
although not necessarily a reliable one. The error is convoluted and
difficult to debug in absence of sources; as such, I cannot offer a
definitive attack scenario, nor rule out that my initial diagnosis will be
proved wrong [*]. As such, panic, but only slightly.

Probably the easiest way to trigger the problem is as follows:

perl -e '{print "<STYLE></STYLE>n<OBJECT>nBorkn"x32}' >test.html

...this will (usually) cause a NULL pointer + fixed offset (eax+0x28)
dereference in mshtml.dll, the pointer being read from allocated but still
zeroed memory region.

The aforementioned condition is not exploitable, but padding the page with
preceeding OBJECT tag (and other tags), increasing the number of nested
OBJECTs, and most importantly, adding bogus 'type=' parameters of various
length to the final sequence of OBJECTs, will cause that dereference to
become non-NULL on many installations; then, a range of other interesting
faults should ensue, including dereferences of variable bogus addresses
close to stack, or crashes later on, when the page is reloaded or closed.

[ In absence of sources, I do not understand the precise underlying
mechanics of the bug, and I am not inclined to spend hours with a
debugger to find out. I'm simply judging by the symptoms, but these
seem to be indicative of an exploitable flaw. ]

Several examples of pages that cause distinct faults in my setup (your
mileage may and probably WILL vary; on three test machines, this worked as
described; on one, all examples behaved in non-exploitable 0x28 way):

http://lcamtuf.coredump.cx/iedie2-1.html (eax=0x0, instant dereference)
http://lcamtuf.coredump.cx/iedie2-2.html (bogus esi on reload/leave)
http://lcamtuf.coredump.cx/iedie2-3.html (page fault on browser close)
http://lcamtuf.coredump.cx/iedie2-4.html (bogus esi on reload/leave)

Well, that's it. Feel free to research this further. This vulnerability,
as requested by customers, is released in strict observance of the Patch
Wednesday & Bug Saturday policy.

[*] The ability of the attacker to document the attack scenario probably
doesn't matter for those who pretend to care; cryptic "hi" to
Secunia and their standards of conduct.

 
Syndication
Permalink Email this

The URI to TrackBack this entry is:
http://www.thebugs.ws/news/trackback.php?id=1655

User comments (post your comments here)

Only registerd members can post comments and articles
 

Previous articleBack to news listNext article
 

 Last security news  Last forum messages
  • Bluesoleil (general bluetooth) drivers update 2.3.060728...
  • Blu-ray, HD DVD DRM busted...
  • FBI database hacked...
  • Phishing by phone...
  • Microsoft France site cracked...
  • Social networks poised to shape Net's future...
  • Windows Vista Beta 2 Available for Public Download...
  • Hacker Steals Energy Department Employee Data...
  • PQI Introduces 64GB NAND Flash 2.5" Disks...
  • MSIE (mshtml.dll) OBJECT tag vulnerability...

    More news... Submit news RSS
  • General / Re: tactictools
  • General / Re: halavwpt
  • General / Re: etap power station 6
  • General / Re: Rip Tiger
  • General / Re: Cannot Access Site/Forum with Internet Exploer
  • General / Re: BusyWin 3.5
  • General / Re: Login & Password Problems for the Site Please Help
  • General / Re: AVS Video Converter 6.2.4.330
  • General / Re: Math Blaster
  • General / Re: Final Cut Studio HD

    Go to forums... RSS

  • CrackPortal.com TheCRACK CrackSpider.DE Need Crack KeyGen.us AllSeek Google FILE HOSTING

    Ya-Cyt SpyLOG - Спайлог Page Rank Checker