Snort mailing list archives

Re: Webkit DoS -- سمَـَّوُوُحخ ̷̴̐خ ̷̴̐خ ̷̴̐خ امارتيخ ̷̴̐خ


From: Joel Esler <jesler () sourcefire com>
Date: Fri, 6 Sep 2013 13:57:00 -0400

Slow clap. 

--
Joel Esler

On Sep 6, 2013, at 12:33 PM, L0rd Ch0de1m0rt <l0rdch0de1m0rt () gmail com> wrote:

Hello.  Whoops, I accidentily sent the last email early (still getting used to the new GMAIL interface and hit the 
wrong key-board combination for my new key-board layout).  Anyway, here is the string:

سمَـَّوُوُحخ ̷̴̐خ ̷̴̐خ ̷̴̐خ امارتيخ ̷̴̐خ

Does anyone know why this happens and what other combination or sub-strings can be used to exploit this? I ask so 
that we can make a SNORT rule for it.  From my reading this is DoS and no RCE or BO that is known of.

Thanks.

Lord C.


On Fri, Sep 6, 2013 at 12:27 PM, L0rd Ch0de1m0rt <l0rdch0de1m0rt () gmail com> wrote:
Hello.  I saw something recently that showed that this Arabic string can DoS Webkit programs:

------------------------------------------------------------------------------
Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more!
Discover the easy way to master current and previous Microsoft technologies
and advance your career. Get an incredible 1,500+ hours of step-by-step
tutorial videos with LearnDevNow. Subscribe today and save!
http://pubads.g.doubleclick.net/gampad/clk?id=58041391&iu=/4140/ostg.clktrk
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!
------------------------------------------------------------------------------
Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more!
Discover the easy way to master current and previous Microsoft technologies
and advance your career. Get an incredible 1,500+ hours of step-by-step
tutorial videos with LearnDevNow. Subscribe today and save!
http://pubads.g.doubleclick.net/gampad/clk?id=58041391&iu=/4140/ostg.clktrk
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!

Current thread: