Clan x86

Technical (Development, Security, etc.) => General Security Information => Topic started by: iago on December 21, 2005, 11:06:56 am

Title: Vuln from... 1995?
Post by: iago on December 21, 2005, 11:06:56 am
http://www.geocities.com/teh_kids/index.html
http://steve.clear-blue.com/index2.html

Since it might get shut down, there's 2 links. 
Title: Re: Vuln from... 1995?
Post by: Newby on December 21, 2005, 01:38:34 pm
That's old. :P
Title: Re: Vuln from... 1995?
Post by: iago on December 21, 2005, 01:41:28 pm
Yeah, but it still affects Windows XP SP2.. that's the funny thing. 

And from what I've read, it's not IE, it's Windows.  It affects any browser. 
Title: Re: Vuln from... 1995?
Post by: Newby on December 21, 2005, 01:41:42 pm
That's saaaaad sad shit.
Title: Re: Vuln from... 1995?
Post by: iago on December 21, 2005, 01:49:25 pm
I just tested it in VMWare.. worked beautifully :)

Title: Re: Vuln from... 1995?
Post by: iago on December 21, 2005, 02:02:31 pm
Check out the link in my signature.. .that's this :)
Title: Re: Vuln from... 1995?
Post by: Chavo on December 21, 2005, 02:50:59 pm
It didn't crash my xp sp2 machine (I'm at work)....
Title: Re: Vuln from... 1995?
Post by: Ergot on December 21, 2005, 03:04:38 pm
Windows 98SE + IE = Nothing
Windows 98SE + Firefox = Nothing
Windows XP SP2 + Firefox = Nothing
Windows XP SP2 + IE = WE HAVE A WINNER ~
Title: Re: Vuln from... 1995?
Post by: Blaze on December 21, 2005, 06:45:17 pm
<3 No SP2. :)
Title: Re: Vuln from... 1995?
Post by: wires on December 21, 2005, 06:50:00 pm
Windows 98SE + IE = Nothing
Windows 98SE + Firefox = Nothing
Windows XP SP2 + Firefox = Nothing
Windows XP SP2 + IE = WE HAVE A WINNER ~
Rebooted me when I used Firefox. :(
Title: Re: Vuln from... 1995?
Post by: Quik on December 21, 2005, 07:48:30 pm
Firefox and SP1 dies. It crashes the video driver, trying to load stoopid.jpg that has width="9999999" height="9999999" .
Title: Re: Vuln from... 1995?
Post by: Newby on December 21, 2005, 08:10:18 pm
Firefox 1.5 (latest) and SP2 lives.
Title: Re: Vuln from... 1995?
Post by: iago on December 21, 2005, 09:35:59 pm
Firefox and SP1 dies. It crashes the video driver, trying to load stoopid.jpg that has width="9999999" height="9999999" .

The actual picture doesn't, but the .html says it does.  On the one on my page (in my signature), I'm just using a screenshot that I had handy :)
Title: Re: Vuln from... 1995?
Post by: Quik on December 21, 2005, 09:39:54 pm
Firefox and SP1 dies. It crashes the video driver, trying to load stoopid.jpg that has width="9999999" height="9999999" .

The actual picture doesn't, but the .html says it does.  On the one on my page (in my signature), I'm just using a screenshot that I had handy :)

What are you trying to say? Please clarify that post, you sound drunk.
Title: Re: Vuln from... 1995?
Post by: deadly7 on December 21, 2005, 09:59:36 pm
Didn't crash me, owned newb.
Title: Re: Vuln from... 1995?
Post by: Joe on December 21, 2005, 10:50:42 pm
Quote
Firefox and SP1 dies. It crashes the video driver

Signed.
Title: Re: Vuln from... 1995?
Post by: deadly7 on December 21, 2005, 11:17:56 pm
That's why you don't use ATI. gg
Title: Re: Vuln from... 1995?
Post by: Quik on December 21, 2005, 11:24:44 pm
That's why you don't use ATI. gg

I'm on an nVidia GeForce.
Title: Re: Vuln from... 1995?
Post by: deadly7 on December 21, 2005, 11:27:38 pm
Well you fail.  I like how it crashes the new cards but my nVIDIA GeForce3 Titanium 200 64mb video card be unaffected.
Title: Re: Vuln from... 1995?
Post by: iago on December 21, 2005, 11:50:36 pm
Firefox and SP1 dies. It crashes the video driver, trying to load stoopid.jpg that has width="9999999" height="9999999" .

The actual picture doesn't, but the .html says it does.  On the one on my page (in my signature), I'm just using a screenshot that I had handy :)

What are you trying to say? Please clarify that post, you sound drunk.

I read over it, and it sounds fine. 

The actual image doesn't have a size of what you said.  The image can be any size. 

The .html tag, on the other hand, resizes the image to something that Windows can't handle. 

Does it work better in smaller words?

Anyway, this is especially fun on:
- SMF forums
- MySpace
:)
Title: Re: Vuln from... 1995?
Post by: Newby on December 21, 2005, 11:59:30 pm
Don't forget IPB boards!
Title: Re: Vuln from... 1995?
Post by: Quik on December 22, 2005, 12:19:12 am
Firefox and SP1 dies. It crashes the video driver, trying to load stoopid.jpg that has width="9999999" height="9999999" .

The actual picture doesn't, but the .html says it does.  On the one on my page (in my signature), I'm just using a screenshot that I had handy :)

What are you trying to say? Please clarify that post, you sound drunk.

I read over it, and it sounds fine. 

The actual image doesn't have a size of what you said.  The image can be any size. 

The .html tag, on the other hand, resizes the image to something that Windows can't handle. 

Does it work better in smaller words?

Anyway, this is especially fun on:
- SMF forums
- MySpace
:)

So the image doesn't matter (not an issue of opening it up in a hex editor and changing specific bytes like other exploits have been), but the HTML code crashing video drivers because it is trying to render too large of an image is the fault? Tell me if I'm mistaken.
Title: Re: Vuln from... 1995?
Post by: iago on December 22, 2005, 12:33:45 am
So the image doesn't matter (not an issue of opening it up in a hex editor and changing specific bytes like other exploits have been), but the HTML code crashing video drivers because it is trying to render too large of an image is the fault? Tell me if I'm mistaken.

In this case, yes.

However, because it happens on different browsers, it is probably deeper than that.  But it definitely has to do with loading an image with a huge size. 
Title: Re: Vuln from... 1995?
Post by: Newby on December 22, 2005, 01:06:18 am
So the image doesn't matter (not an issue of opening it up in a hex editor and changing specific bytes like other exploits have been), but the HTML code crashing video drivers because it is trying to render too large of an image is the fault? Tell me if I'm mistaken.

In this case, yes.

However, because it happens on different browsers, it is probably deeper than that.  But it definitely has to do with loading an image with a huge size. 

It's probably the fact that Windows attempts to resize an image to an amazingly large size, and can't do this because it sucks!
Title: Re: Vuln from... 1995?
Post by: Ergot on December 22, 2005, 01:52:18 am
Bad picture but meh...
Title: Re: Vuln from... 1995?
Post by: iago on December 22, 2005, 03:57:48 am
Oh yeah?

(http://www.javaop.com/~iago/bs.png)

Much prettier :)

Also note that Windows' Bluescreen takes 100% cpu usage.  *wonders why*
Title: Re: Vuln from... 1995?
Post by: Screenor on December 29, 2005, 05:13:42 am
There was a similar bug to this a while back that worked on all browsers, just it involved making a .gif 9999 (literally) times it's size, it was patched pretty quickly with Firefox, though.

My favorite atm is http://aquabelic.tk/
Title: Re: Vuln from... 1995?
Post by: Sidoh on December 29, 2005, 03:00:40 pm
ROFL.  That's sad.
Title: Re: Vuln from... 1995?
Post by: RoMi on December 31, 2005, 10:46:08 pm
In Media Center 05 it doesn't crash.  Firefox handels it.  IE becomes unresponsive needing to be closed with ALT-F4 or ALT-CTRL-DEL.  No crashing however.
Title: Re: Vuln from... 1995?
Post by: Warrior on January 03, 2006, 02:06:06 am
in XP SP2 with Firefox 1.5 it blue screens, pre 1.5 it just restarted.