// COMPLETE THREAD

Re: Another Netscape Bug (and possible security hole)

16 expanded posts ยท every known parent and child

NODE 81f44f0eRe: Another Netscape Bug (and possible security hole)
-----BEGIN PGP SIGNED MESSAGE-----

>Ray Cromwell writes:
>> I've found a Netscape bug which I suspect is a buffer overflow and
>> may have the potential for serious damage. If it is an overflow bug,
>> then it may be possible to infect every computer which accesses a web
>> page with Netscape. To see the bug, create an html file containing
>> the following:
>
>Oh brother, this is unbelievable !
>
>I'm using Netscape 1.1N under SunOS 4.1.2.
>
>It turns out that the same (or a similar) flaw resides in the Open Location
>input routine -- perhaps this merely coincides with the code called when a
>URL is clicked. Anyway, pasting a URL with an overlong domain name a la
Ray's
>example causes two things:
>
>(1) Part of the Open Location window widget, below the entry box, gets
>overwritten onscreen with a portion of the entered URL.
>
>(2) Netscape crashes with a segmentation fault (no core dump that I can
see).

Netscape 1.1N on a powermac crashes hard on that url. If anyone wants to try
it out, I've put up a simple page with the url at

http://www.redweb.com/experiment/bug.html

*warning* view the source before you click on strange links!!!

I don't do PPC assembler, so I can't tell you what happened.


-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQBgAwUBMGJysHIf3YegbdiBAQF/RAJWNVXvLgyPEjVVoGUNoX/AqKlIiT5Axmek
+dCoGJy6CMcP7fq3rB+DAt+SziIaG2X+rUSLt8ih39TBjD1FLAKKsE/VhBHJrp+v
pSoO
=jfLP
-----END PGP SIGNATURE-----
NODE ca2ddc83Re: Another Netscape Bug (and possible security hole)
OK, Perry was right, and it was wrong of me to argue with him based
only on the code that I have personally seen.  As we have already
determined, I have not reviewed every line of code in netscape.

  Not that I want to divert attention away from netscape(OK, maybe I
do :-) ), but does this bug exist in any other common browser?

	--Jeff

-- 
Jeff Weinstein - Electronic Munitions Specialist
Netscape Communication Corporation
jsw@netscape.com - http://home.netscape.com/people/jsw
Any opinions expressed above are mine.
NODE a6188b13Mosaic Bug (same as Netscape bug) (was Re: Another Netscape Bug)
Jeff Weinstein writes:
>   Not that I want to divert attention away from netscape(OK, maybe I
> do :-) ), but does this bug exist in any other common browser?

Good question.

Here's one answer, obtained using a minor variation on Ray's URL:

----------------------------------------------
Congratulations, you have found a bug in
NCSA Mosaic 2.4 on Sun.

If a core file was generated in your directory,
please run 'dbx Mosaic' (or 'dbx /path/Mosaic' if the
Mosaic executable is not in your current directory)
and then type:
  dbx> where
and mail the results, and a description of what you were doing at the time,
to mosaic-x@ncsa.uiuc.edu.  We thank you for your support.

...exiting NCSA Mosaic now.
----------------------------------------------------

Now, the question is, does Netscape use _the same code_ that was used in
Mosaic for this purpose ?

-Futplex <futplex@pseudonym.com>
NODE dd84f5a5Re: Mosaic Bug (same as Netscape bug) (was Re: Another Netscape Bug)
In article <9509220801.AA06875@cs.umass.edu>, futplex@pseudonym.com (Futplex) writes:
> Now, the question is, does Netscape use _the same code_ that was used in
> Mosaic for this purpose ?

  Absolutely not.  There is not a single line of Mosaic code in our product.

	--Jeff

-- 
Jeff Weinstein - Electronic Munitions Specialist
Netscape Communication Corporation
jsw@netscape.com - http://home.netscape.com/people/jsw
Any opinions expressed above are mine.
NODE fa6cf805Re: Another Netscape Bug (and possible security hole)
Jeff Weinstein writes:
>   OK, Perry was right, and it was wrong of me to argue with him based
> only on the code that I have personally seen.  As we have already
> determined, I have not reviewed every line of code in netscape.
> 
>   Not that I want to divert attention away from netscape(OK, maybe I
> do :-) ), but does this bug exist in any other common browser?

Probably in Mosaic, though not necessarily in the same place. Its a
case of the same programmers making the same mistakes over and over
again.

I don't believe the Sun Java stuff would suffer from it, although I
fear Java a great deal.

Perry
NODE f7313a67Re: Another Netscape Bug (and possible security hole)
> I don't believe the Sun Java stuff would suffer from it, although I
> fear Java a great deal.

Java's doesn't break on this one. All you get back is a message saying the 
domain isn't defined.

BTW: This was tested using 

http://foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.
foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo
.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.fo
o.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.f
oo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.
foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo
.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.fo
o.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.f
oo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.
foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo
.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.fo
o.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo.foo/

on a SunOS box using HotJava 1.0 alpha 3.

Scott
--
Scott Fabbri                                  sfabbri@frb.gov
Opinions solely my own -- who else would want them?
NODE 8dc8f793Re: Another Netscape Bug (and possible security hole)
Perry E. Metzger wrote:

| I don't believe the Sun Java stuff would suffer from it, although I
| fear Java a great deal.

	I keep hearing this thought.  Isn't Win95 with its
'executables in email' much more dangerous than Java, which at least
tries to address security?

	There is the argument that the claims will inspire false
confidence in Java's security mechanisms, and thus people will be
bitten, but I don't buy it.  People don't look to security as a chack
item when buying software.  And when they do, they're usually not
capable of distinguishing between the pap that passes for security
through marketing from security by design.

Adam

-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume
NODE b4f94e53Re: Another Netscape Bug (and possible security hole)
On Fri, 22 Sep 1995, Adam Shostack wrote:

> Perry E. Metzger wrote:
> 
> | I don't believe the Sun Java stuff would suffer from it, although I
> | fear Java a great deal.
> 
> 	I keep hearing this thought.  Isn't Win95 with its
> 'executables in email' much more dangerous than Java, which at least
> tries to address security?

Is that the new MS-Word you're thinking of?  I hear that it lets you
imbed macros containing executable code in documents.  That's got to
be one of the most dangerous ideas ever cooked up.

   --Dave.

--
Dave Mandl
dmandl@panix.com
http://wfmu.org/~davem
NODE 3bc2a4c0Re: Another Netscape Bug (and possible security hole)
dmandl@panix.com wrote:
| On Fri, 22 Sep 1995, Adam Shostack wrote:

| > 	I keep hearing this thought.  Isn't Win95 with its
| > 'executables in email' much more dangerous than Java, which at least
| > tries to address security?
| 
| Is that the new MS-Word you're thinking of?  I hear that it lets you
| imbed macros containing executable code in documents.  That's got to
| be one of the most dangerous ideas ever cooked up.

	No, this is a seperate problem.  Its not auto-executing code
in Microsoft documents that worries me, so much as the ability to
include executables as clickable images in a mail message, with the
user having no control over what environment the program executes in.

	If strong fences make good neighbors, where are the fences in
my network neighborhood?

Adam

-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume
NODE a1fa267fRe: Another Netscape Bug (and possible security hole)
Actually it allows you to imbed data and commands to run. What the latest
MSWord virus did is imbed a virus dropper encoded in the word document
and then run it trough the dos debug command to make it a binary file
(if you ever read the 40HEX virus magazine you should know how this works).
From there it just run the dropper.

Aleph One / aleph1@dfw.net
http://underground.org/
KeyID 1024/948FD6B5 
Fingerprint EE C9 E8 AA CB AF 09 61  8C 39 EA 47 A8 6A B8 01 

On Fri, 22 Sep 1995 dmandl@panix.com wrote:

> Is that the new MS-Word you're thinking of?  I hear that it lets you
> imbed macros containing executable code in documents.  That's got to
> be one of the most dangerous ideas ever cooked up.
> 
>    --Dave.
> 
> --
> Dave Mandl
> dmandl@panix.com
> http://wfmu.org/~davem
>
NODE 8ffbd506Re: Another Netscape Bug (and possible security hole)
> 
> Actually it allows you to imbed data and commands to run. What the latest
> MSWord virus did is imbed a virus dropper encoded in the word document
> and then run it trough the dos debug command to make it a binary file
> (if you ever read the 40HEX virus magazine you should know how this works).
> From there it just run the dropper.

  You could make a worm out of this Netscape bug by having it look
for a user's homepage when it infects, and then inserting the
URL into that page.
NODE aa3a871eRe: Another Netscape Bug (and possible security hole)
On Fri, 22 Sep 1995 dmandl@panix.com wrote:

> On Fri, 22 Sep 1995, Adam Shostack wrote:
> 
> > Perry E. Metzger wrote:
> > 
> > | I don't believe the Sun Java stuff would suffer from it, although I
> > | fear Java a great deal.
> > 
> > 	I keep hearing this thought.  Isn't Win95 with its
> > 'executables in email' much more dangerous than Java, which at least
> > tries to address security?
> 
> Is that the new MS-Word you're thinking of?  I hear that it lets you
> imbed macros containing executable code in documents.  That's got to
> be one of the most dangerous ideas ever cooked up.

Agreed; but it's present, not just in Word (every version since 2.0, as 
far as I can tell, in fact, since they all let you make system calls...), 
but in Microsoft Network, Microsoft Access, Microsoft Excel... I believe 
PowerPoint and Publisher are exempt from this bug, if only because the 
current versions have no macro languages...

One of the penalties that modern software (at least for Windows) imposes 
is the ability to create massive viri, simply by allowing system calls to 
be executed from macros (if this was not the case, OLE technology 
wouldn't work, and interoperation between Windows programs can't occur, 
thereby crippling the system through bad design regardless of which 
alternative was chosen)

Jon
------------------------------------------------------------------------------
Jon Lasser                <jlasser@rwd.goucher.edu>            (410)494-3072 
          Visit my home page at http://www.goucher.edu/~jlasser/
  You have a friend at the NSA: Big Brother is watching. Finger for PGP key.
NODE 07770f61Re: Another Netscape Bug (and possible security hole)
-----BEGIN PGP SIGNED MESSAGE-----

While browsing my mail I noticed that Jeff Weinstein wrote:
> 
>   OK, Perry was right, and it was wrong of me to argue with him based
> only on the code that I have personally seen.  As we have already
> determined, I have not reviewed every line of code in netscape.
> 
>   Not that I want to divert attention away from netscape(OK, maybe I
> do :-) ), but does this bug exist in any other common browser?
> 
> 	--Jeff
> 
> -- 
> Jeff Weinstein - Electronic Munitions Specialist
> Netscape Communication Corporation
> jsw@netscape.com - http://home.netscape.com/people/jsw
> Any opinions expressed above are mine.
 

TkWWW under Linux 1.2.12 dies with a Segmentation Fault
with this bug :(


- -- 
=====================PGP Encrypted Mail Preferred========================
       PGP Public Keys: 1024/BEB3ED71 & 2047/D9E1F2E9 on request. 
           As soon as any man says of the affairs of the state 
    " What does it matter to me? " the state may be given up for lost.
                    J.J.Rousseau - The Social Contract
GAT/E/O d++@>- H--- s: a29 C+++$ UL++++($) P+>+++ L++>++++ E W+++ N++ K- 
w---- O- M- V-- PS+ PE++ Y+ PGP+++ t 5+ X R* tv b++ DI++ D++ G++ e h+ r 
y++ [Geek Code v3.0] a.k.a [ root@magus.dgsys.com / vamagus@delphi.com]
==========================================================================

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAgUBMGMWyLbmxeO+s+1xAQEa4gP8DLVEoZwrVtqMpztIrCH6sSAdEoUZf3jU
c2AgSNwvqv4/CbGeTxZ7UBFO4hjbUJPlmvwfY0J6yAfsKnYvSxKL55VtbAQzSuac
2KjUSIUh23wpe9hpJaURpK8NM6tlDs2GsoVmdIRL1wFpdwurAeijH1JhSqrJFdKN
b+/jeyTw9+0=
=7ZJq
-----END PGP SIGNATURE-----
NODE 0dd2ba2bRe: Another Netscape Bug (and possible security hole)
> > 
> >   Not that I want to divert attention away from netscape(OK, maybe I
> > do :-) ), but does this bug exist in any other common browser?
> > 
> > 	--Jeff

	This shows that Netscape will probably, after much bad press
and sleepless nights on the part of netscape developers, become one of
the best secure programs out there.
	The cypherpunks will have won because there will be a secure
program available with the backing of lawyers.
	Netscape will have won because their product will be the best.

-- 
sameer						Voice:   510-601-9777
Community ConneXion				FAX:	 510-601-9734
An Internet Privacy Provider			Dialin:  510-658-6376
http://www.c2.org (or login as "guest")			sameer@c2.org
NODE 44f68106Re: Another Netscape Bug (and possible security hole)
On Fri, 22 Sep 1995, Dietrich J. Kappe wrote:

> Netscape 1.1N on a powermac crashes hard on that url. If anyone wants to try
> it out, I've put up a simple page with the url at
> 

Netscape, Windows (its a school computer) works fine w/ a proxy.
When there is no proxy, Windows dies. EMM dies. Lots of stuff dies.
So use a proxy.

> http://www.redweb.com/experiment/bug.html
> 
> *warning* view the source before you click on strange links!!!

Sometimes you won't expect it, ie for netscape enhancements click
here (or on the Netscape logo).

+---- Yih-Chun Hu (finger:yihchun@cs.washington.edu) ----------------------+
| http://www.cs.washington.edu/homes/yihchun     yihchun@cs.washington.edu |
| http://weber.u.washington.edu/~yihchun         yihchun@u.washington.edu  |
+---- PGP Key Fingerprints (Keys by FINGER or on WWW) ---------------------+
| 1024/E50EC641        B2 A0 DE 9E 36 C0 EB A6  F9 3E D2 DD 2F 27 74 79    |
| 2047/DF0403F9        18 EB 62 C8 7F 06 04 67  42 76 24 E2 99 D1 07 DC    |
+--------------------------------------------------------------------------+
NODE c9ca1fb9Re: Another Netscape Bug (and possible security hole)
On Fri, 22 Sep 1995, Dietrich J. Kappe wrote:

> Netscape 1.1N on a powermac crashes hard on that url. If anyone wants to try
> it out, I've put up a simple page with the url at
> http://www.redweb.com/experiment/bug.html

Netscape also crashes (error 1) on regular Macs...sigh.  I'm contacting 
someone who just wrote a http server to see how tough it would be drop 
some code on the stack.

-Thomas