This blog will contain non-technical, fun and personal posts. All my technical posts will be posted on SMD's blog, http://www.smd.com.my. Looking forward to see you there! :-)

Firefox Code Execution Exploit

Ini adalah demo untuk Firefox 1.0.4 Code Execution Exploit.
The “Set As Wallpaper” dialog takes the image url as a parameter without validating it. This allows to execute javascript in chrome and to run arbitrary code. By using absolute positioning and the moz-opacity filter an attacker can easily fool the user to think he is [...]