|
Full Disclosure
mailing list archives
RE: Local DoS in windows.
From: Steve Wray <steve.wray () paradise net nz>
Date: Sat, 11 Oct 2003 09:10:49 +1300
How long do you have to hold the mouse button down for?
I see no effect after about 30 seconds then I got bored...
Tried in outlook and wordpad. In fact the 'ambient' CPU useage
actually appeared to flatten out.
-----Original Message-----
From: full-disclosure-admin () lists netsys com
[mailto:full-disclosure-admin () lists netsys com] On Behalf Of
bipin gautam
Sent: Saturday, 11 October 2003 6:18 a.m.
To: Full-Disclosure () lists netsys com
Cc: bugtraq () securityfocus com
Subject: [Full-disclosure] Local DoS in windows.
--- [Affected] ---
We have only tried it in windows Xp.
--- [Bug Details] ---
http://www.geocities.com/visitbipin/win_dos.jpg
The image is self explanatory...
--- [Description] ---
When you click to "any" close, maximize or minimize
button's in windows Xp, [No matter whether it's IE or
a WordPad] surprisingly there is 100% CPU use at the
instant and it continues............ until you release
the button! Moreover, we've noticed if you
continuously click the button for a long time [... not
release it and hold ON ] we've seen gradual/slow rise
in page-file use too...!!!
--- [Conclusion] ---
Hell... local DoS! That could be used by employees
working at different terminal..... (O;
--- [Background Information] ---
This bug was originally discovered by hUNT3R,[myself]
a member of 01 Security Submission. The vendor was
notified via email.
http://www.ysgnet.com/hn
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
By Date
By Thread
Current thread:
|