Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 07-19-2007, 11:11 AM   #1
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
:stop Firefox exploit critical !!

Came across a firefox exploit while looking for something from a gfy thread .

this one is being used right now so watch out if your surfing around..

funny thing is that ie blames firefox and firefox blames ie.. and it seems like it only works in ie. but uses firefox for the exploit in the URI handler

this example may or may not work for you , its COMPLETELY SAFE

http://com.webspacemania.com/fox/
test 2
http://com.webspacemania.com/fox2/
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:19 AM   #2
Barefootsies
Choice is an Illusion
 
Barefootsies's Avatar
 
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
:2cents

Quote:
Originally Posted by SmokeyTheBear View Post
Came across a firefox exploit while looking for something from a gfy thread .

this one is being used right now so watch out if your surfing around..

funny thing is that ie blames firefox and firefox blames ie.. and it seems like it only works in ie. but uses firefox for the exploit in the URI handler

this example may or may not work for you , its COMPLETELY SAFE

http://com.webspacemania.com/fox/
test 2
http://com.webspacemania.com/fox2/
__________________
Should You Email Your Members?

Link1 | Link2 | Link3

Enough Said.

"Would you rather live like a king for a year or like a prince forever?"
Barefootsies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:19 AM   #3
sortie
Confirmed User
 
sortie's Avatar
 
Industry Role:
Join Date: Mar 2007
Posts: 7,771
Don't want to click so please explain.
sortie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:20 AM   #4
Deej
I make pixels work
 
Deej's Avatar
 
Industry Role:
Join Date: Jun 2005
Location: I live here...
Posts: 24,386
Smokey.... i use firefox mostly, hwo do i avoid this? i rea dup on this and then firefox says its a stink being raised by IE, but false...


id rely on your words more than either of them...

whats up yo
__________________

Deej's Designs n' What Not
Hit me up for Design, CSS & Photo Retouching


Icq#30096880
Deej is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:22 AM   #5
DomP_nl
So Fucking What
 
DomP_nl's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: 128579
Posts: 631
Both give me a error message it cant handle something, empty square with process.init(file);process.run(true,{},0);alert(pr ocess) .. FF 2.0.0.5















OSX
DomP_nl is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:22 AM   #6
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by sortie View Post
Don't want to click so please explain.
well critical implies usually that your system can be compromised . ie run exe of choice

the example just runs a message on cmd.exe does nothing bad.

when i tested it in my fully patched ie7 xpsp2 it works.

i went looking for it when biskoppen mentioned getting a trojan in another thread using firefox on pichunter
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:24 AM   #7
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by Deej View Post
Smokey.... i use firefox mostly, hwo do i avoid this? i rea dup on this and then firefox says its a stink being raised by IE, but false...


id rely on your words more than either of them...

whats up yo

both i suppose but im no authority on this anyways. not that i would trust them any more , but my take is its a handler not setup properly . so firefox is to blame for registering such an open handler ie is to blame for letting them lol
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:27 AM   #8
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by DomP_nl View Post


OSX

no fair..
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:28 AM   #9
D
Confirmed User
 
D's Avatar
 
Join Date: Jan 2006
Location: The Valley
Posts: 7,412
Thanks for the heads up, Smokey...

You kinda realize when you regard someone as stand-up whenever you blindly charge into clicking on such links when directed to by them.

Neither link successfully executed anything on my end... using Firefox 2.0.0.4... Win XP

A warning came up, instead - alerting me that the launching of an external application was required to proceed, and prompted if I wanted to launch it or not.

Was this the reason for the new update, or does this take advantage of the recent update?

I have it downloaded, but have yet to install 2.0.0.5
__________________
-D.
ICQ: 202-96-31
D is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:30 AM   #10
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by Deej View Post
hwo do i avoid this?
well there is one thing you could avoid..


make sure your firefox is setup as default browser, i have a feeling ie might leave it open to make firefox fix it. i think it relies on ie being used , there are ways to force firefox to open internet explorer if its set to default browser
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:37 AM   #11
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by D View Post
Thanks for the heads up, Smokey...

You kinda realize when you regard someone as stand-up whenever you blindly charge into clicking on such links when directed to by them.

Neither link successfully executed anything on my end... using Firefox 2.0.0.4... Win XP

A warning came up, instead - alerting me that the launching of an external application was required to proceed, and prompted if I wanted to launch it or not.

Was this the reason for the new update, or does this take advantage of the recent update?

I have it downloaded, but have yet to install 2.0.0.5
well in this example i think it requires you to be using internet explorer , but the exploit is caused by firefox, but its very easy to get firefox to open internet explorer , so i could make it a bit better and force firefox to open ie . ill make another example to show its possible.
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 11:40 AM   #12
D
Confirmed User
 
D's Avatar
 
Join Date: Jan 2006
Location: The Valley
Posts: 7,412
Quote:
Originally Posted by SmokeyTheBear View Post
well in this example i think it requires you to be using internet explorer , but the exploit is caused by firefox, but its very easy to get firefox to open internet explorer , so i could make it a bit better and force firefox to open ie . ill make another example to show its possible.
ahh... I misunderstood.

Thanks.
__________________
-D.
ICQ: 202-96-31
D is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 12:11 PM   #13
fuzebox
making it rain
 
fuzebox's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: seattle
Posts: 22,054
Quote:
Originally Posted by DomP_nl View Post
Both give me a error message it cant handle something, empty square with process.init(file);process.run(true,{},0);alert(pr ocess) .. FF 2.0.0.5


OSX
Same on Linux

Errr I misunderstood that it's actually an IE hole that uses firefox.
fuzebox is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-19-2007, 05:53 PM   #14
modelscanada
Registered User
 
Join Date: Jul 2007
Posts: 31
are you for real???
modelscanada is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.