Os reproduzco el mail del autor del PoC:
Citar
About a year ago I came across this same issue. I came across it while
messing with Solar Designer's old Netscape JPEG bug. So, in short the same
issue applies to WinXP it seems. I showed the bug to a few people (even
contacted Microsoft, but got no reply), but neither them nor myself ever got
around to figuring it out. Nick DeBaggis and eEye did a good job of figuring
this very dangerous issue out
Anyway, the point to this post is to release the POC I just put together
using the findings that I have been sitting on for quite some time. As I
said before, I never fully understood exactly what was going on, so this POC
doesn't execute code or anything, but it will crash any WindowsXP machine
that has not been patched from this flaw.
If you cannot access the attached file, you may download the POC here
http://www.gulftech.org/?node=downloads
BTW: There was a BugTraq (or some other sec mailing list) post from over a
year ago that talks about the Netscape JPEG issue crashing the WindowsXP
Shell. I remember seeing them when I first started looking into this issue,
but do not have links right off hand. Maybe someone else reading this does?
messing with Solar Designer's old Netscape JPEG bug. So, in short the same
issue applies to WinXP it seems. I showed the bug to a few people (even
contacted Microsoft, but got no reply), but neither them nor myself ever got
around to figuring it out. Nick DeBaggis and eEye did a good job of figuring
this very dangerous issue out

Anyway, the point to this post is to release the POC I just put together
using the findings that I have been sitting on for quite some time. As I
said before, I never fully understood exactly what was going on, so this POC
doesn't execute code or anything, but it will crash any WindowsXP machine
that has not been patched from this flaw.
If you cannot access the attached file, you may download the POC here
http://www.gulftech.org/?node=downloads
BTW: There was a BugTraq (or some other sec mailing list) post from over a
year ago that talks about the Netscape JPEG issue crashing the WindowsXP
Shell. I remember seeing them when I first started looking into this issue,
but do not have links right off hand. Maybe someone else reading this does?
En el link, esta la descarga del exploit. A mi me ha petado el explorer, es decir, soy vulnerable (y me estoy cagando en M$ porque no encuentro el parche). Si conseguis ver el readme xD (no es tan dificil xD), vereis como "fabricar" un jpg "malicioso".
Lo curioso es que la herramienta para hacerlo, tiene ya un año, y se hizo para usarla en un bug JPG que afectaba a Windows XP y a Netscape.
En fin, cosas que pasan....
Salu2










Autor





En línea







