Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: [Full-disclosure] 4 Questions: Latest IE vulnerability, Firefox vs IE security, User vs Admin risk profile, and browsers coded in 100% Managed Verifiable code

Re: [Full-disclosure] 4 Questions: Latest IE vulnerability, Firefox vs IE security, User vs Admin risk profile, and browsers coded in 100% Managed Verifiable code

From: Brian Eaton <eaton.lists_at_gmail.com>
Date: Wed, 29 Mar 2006 10:14:51 -0500

On 3/28/06, michaelslists_at_gmail.com <michaelslists_at_gmail.com> wrote:
> no, a browser written in java would not have buffer overflow/stack
> issues. the jvm is specifically designed to prevent it ...
>
> -- Michael
>
> On 3/29/06, Pavel Kankovsky <peak_at_argo.troja.mff.cuni.cz> wrote:
> > On Mon, 27 Mar 2006, Brian Eaton wrote:
> >
> > > If I run a pure-java browser, for example, no web site's HTML code is
> > > going to cause a buffer overflow in the parser.
> >
> > Even a "pure-java browser" would rest on the top of a huge pile of native
> > code (OS, JRE, native libraries). A seemingly innocent piece of data
> > passed to that native code might trigger a bug (perhaps even a buffer
> > overflow) in it...
> >
> > Unlikely (read: less likely than a direct attack vector) but still
> > possible.

Pavel is talking about native code, which the JVM needs to interface
to the rest of the OS. Native code can have buffer overflows, and
those bugs can be exploitable.

For example: http://www.appsecinc.com/resources/alerts/general/WEBSPHERE-001.html

The risk is several orders of magnitude less, but it is there.

Regards,
Brian

-------------------------------------------------------------------------
This List Sponsored by: SpiDynamics

ALERT: "How A Hacker Launches A Web Application Attack!"
Step-by-Step - SPI Dynamics White Paper
Learn how to defend against Web Application Attacks with real-world
examples of recent hacking methods such as: SQL Injection, Cross Site
Scripting and Parameter Manipulation

https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=701300000003gRl
--------------------------------------------------------------------------
Received on Mar 29 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos