Re: [newbie] Exploit in Java for Netscape

1999-07-12 Thread Civileme

"James J. Capone" wrote:

 I found a Exploit in All Internet browsers that support Java. The only way this
 works is to have Java Running..

 Here it is though:

H

Well, there are some nice exploits at www.insecure.org, too.

I managed to avoid it with kfm.  I don't know if kfm had java running or not.

Civileme



Re: [newbie] Exploit in Java for Netscape

1999-07-12 Thread Don Kelley

uh, hi.  Have you been programming "Java" for long?  Because the language
you're showing here is Javascript, not Java.  It's a completely different
language, and there is no way to have inline Java with html statements as
Java is (more or less) a compiled language while Javascript is interpreted
(and can be parsed by browsers on the fly along with HTML statements).  Or
am I wrong about this?

and anyway, what's your point?  Every programmer can write bad code that
loops badly - and the code in your example here can be done much more easily
within a loop.  That is, if you actually want to create a useless web page
that crashes people's browsers that have JAVASCRIPT enabled, not java

Don
-

-Original Message-
From: James J. Capone [EMAIL PROTECTED]
To: '[EMAIL PROTECTED]' [EMAIL PROTECTED]
Date: Sunday, July 11, 1999 10:13 PM
Subject: [newbie] Exploit in Java for Netscape


I found a Exploit in All Internet browsers that support Java. The only way
this
works is to have Java Running..

Here it is though:

BODY onLoad="alert('Welcome to my test!  Full of examples, tutorials,
scripts,
and links!  All for FREE!!  Check it out!');" onUnLoad="confirm('Are you
sure
you want to leave this
page?');parent.close();parent.close();parent.close();parent.close();parent.
c
lose();parent.close();parent.close();parent.close();parent.close();parent.c
l
ose();parent.close();parent.close();parent.close();parent.close();parent.cl
o
se();parent.close();parent.close();parent.close();parent.close();parent.clo
s
e();parent.close();parent.close();parent.close();parent.close();parent.clos
e
();parent.close();parent.close();parent.close();parent.close();parent.close
(  
);parent.close();parent.close();parent.close();parent.close();parent.close()  
;parent.close();parent.close();parent.close();parent.close();parent.close();  
parent.close();parent.close();parent.close();parent.close();parent.close();p  
arent.close();parent.close();parent.
close();parent.close();parent.close();pa
rent.close();parent.close();parent.close();parent.close();parent.close();pa
r
ent.close();parent.close();parent.close();parent.close();parent.close();par
e
nt.close();parent.close();parent.close();parent.close();parent.close();pare
n
t.close();parent.close();parent.close();parent.close();parent.close();paren
t
.close();parent.close();parent.close();parent.close();parent.close();parent
.
close();parent.close();parent.close();parent.close();parent.close();parent.
c
lose();parent.close();parent.close();parent.close();parent.close();parent.c
l
ose();parent.close();parent.close();parent.close();parent.close();parent.cl
o
se();parent.close();parent.close();parent.close();parent.close();parent.clo
s
e();parent.close();parent.close();parent.close();parent.close();parent.clos
e
();parent.close();parent.close();parent.close();parent.close();parent.close
(  
);parent.close();parent.close();parent.close();parent.close();parent.close()  
;parent.close();parent.close();parent.close();parent.close();parent.close();  
parent.close();parent.close();parent.close();parent.close();parent.close();p  
arent.close();parent.close();parent.close();parent.close();parent.close();pa  
rent.close();parent.close();parent.close();parent.close();parent.close();par  
ent.close();parent.close();parent.close();parent.close();parent.close();pare  
nt.close();parent.close();parent.close();parent.close();parent.close();paren  
t.close();parent.close();parent.close();parent.close();parent.close();parent  
.close();parent.close();parent.close();parent.close();parent.close();parent.  
close();parent.close();parent.close();parent.close();parent.close();parent.c  
lose();parent.close();parent.close();parent.close();parent.close();parent.cl  
ose();parent.close();parent.close();parent.close();parent.close();parent.clo  
se();parent.close();parent.close();parent.close();parent.close();parent.clos  
e();parent.close();parent.close();parent.close();parent.clo
se();parent.close
();parent.close();parent.close();parent.close();parent.close();parent.close
(  
);parent.close();parent.close();parent.close();parent.close();parent.close()  
;parent.close();parent.close();parent.close();parent.close();parent.close();  
parent.close();parent.close();parent.close();parent.close();parent.close();p  
arent.close();parent.close();parent.close();parent.close();parent.close();pa  
rent.close();parent.close();parent.close();parent.close();parent.close();par  
ent.close();parent.close();parent.close();parent.close();parent.close();pare  
nt.close();parent.close();parent.close();parent.close();parent.close();paren  
t.close();parent.close();parent.close();parent.close();parent.close();parent  
.close();parent.close();parent.close();parent.close();parent.close();parent.  
close();parent.close();parent.close();parent.close();parent.close();parent.c  
lose();parent.close();parent.close();parent.close();parent.close();parent.cl  

Re: [newbie] Exploit in Java for Netscape

1999-07-12 Thread Don Kelley

kfm doesn't run java.  It may run Javascript, but I doubt it.  These are
different languages everyone.  They sound similar but if you can program in
one it's unlikely you can program in the other without further study.

Don
-Original Message-
From: Civileme [EMAIL PROTECTED]
To: [EMAIL PROTECTED] [EMAIL PROTECTED]
Date: Monday, July 12, 1999 2:26 AM
Subject: Re: [newbie] Exploit in Java for Netscape


"James J. Capone" wrote:

 I found a Exploit in All Internet browsers that support Java. The only
way this
 works is to have Java Running..

 Here it is though:

H

Well, there are some nice exploits at www.insecure.org, too.

I managed to avoid it with kfm.  I don't know if kfm had java running or
not.

Civileme




Re: [newbie] Exploit in Java for Netscape

1999-07-12 Thread Bert Bullough

watch out don, the script kiddie might get angry and 0V/ |V \/

Don Kelley wrote:

 uh, hi.  Have you been programming "Java" for long?  Because the language
 you're showing here is Javascript, not Java.  It's a completely different
 language, and there is no way to have inline Java with html statements as
 Java is (more or less) a compiled language while Javascript is interpreted
 (and can be parsed by browsers on the fly along with HTML statements).  Or
 am I wrong about this?

 and anyway, what's your point?  Every programmer can write bad code that
 loops badly - and the code in your example here can be done much more easily
 within a loop.  That is, if you actually want to create a useless web page
 that crashes people's browsers that have JAVASCRIPT enabled, not java

 Don
 -

 -Original Message-
 From: James J. Capone [EMAIL PROTECTED]
 To: '[EMAIL PROTECTED]' [EMAIL PROTECTED]
 Date: Sunday, July 11, 1999 10:13 PM
 Subject: [newbie] Exploit in Java for Netscape

 I found a Exploit in All Internet browsers that support Java. The only way
 this
 works is to have Java Running..
 
 Here it is though:
 
 BODY onLoad="alert('Welcome to my test!  Full of examples, tutorials,
 scripts,
 and links!  All for FREE!!  Check it out!');" onUnLoad="confirm('Are you
 sure
 you want to leave this
 page?');parent.close();parent.close();parent.close();parent.close();parent.
 c
 lose();parent.close();parent.close();parent.close();parent.close();parent.c
 l
 ose();parent.close();parent.close();parent.close();parent.close();parent.cl
 o
 se();parent.close();parent.close();parent.close();parent.close();parent.clo
 s
 e();parent.close();parent.close();parent.close();parent.close();parent.clos
 e
 ();parent.close();parent.close();parent.close();parent.close();parent.close
 (
 );parent.close();parent.close();parent.close();parent.close();parent.close()
 ;parent.close();parent.close();parent.close();parent.close();parent.close();
 parent.close();parent.close();parent.close();parent.close();parent.close();p
 arent.close();parent.close();parent.
 close();parent.close();parent.close();pa
 rent.close();parent.close();parent.close();parent.close();parent.close();pa
 r
 ent.close();parent.close();parent.close();parent.close();parent.close();par
 e
 nt.close();parent.close();parent.close();parent.close();parent.close();pare
 n
 t.close();parent.close();parent.close();parent.close();parent.close();paren
 t
 .close();parent.close();parent.close();parent.close();parent.close();parent
 .
 close();parent.close();parent.close();parent.close();parent.close();parent.
 c
 lose();parent.close();parent.close();parent.close();parent.close();parent.c
 l
 ose();parent.close();parent.close();parent.close();parent.close();parent.cl
 o
 se();parent.close();parent.close();parent.close();parent.close();parent.clo
 s
 e();parent.close();parent.close();parent.close();parent.close();parent.clos
 e
 ();parent.close();parent.close();parent.close();parent.close();parent.close
 (
 );parent.close();parent.close();parent.close();parent.close();parent.close()
 ;parent.close();parent.close();parent.close();parent.close();parent.close();
 parent.close();parent.close();parent.close();parent.close();parent.close();p
 arent.close();parent.close();parent.close();parent.close();parent.close();pa
 rent.close();parent.close();parent.close();parent.close();parent.close();par
 ent.close();parent.close();parent.close();parent.close();parent.close();pare
 nt.close();parent.close();parent.close();parent.close();parent.close();paren
 t.close();parent.close();parent.close();parent.close();parent.close();parent
 .close();parent.close();parent.close();parent.close();parent.close();parent.
 close();parent.close();parent.close();parent.close();parent.close();parent.c
 lose();parent.close();parent.close();parent.close();parent.close();parent.cl
 ose();parent.close();parent.close();parent.close();parent.close();parent.clo
 se();parent.close();parent.close();parent.close();parent.close();parent.clos
 e();parent.close();parent.close();parent.close();parent.clo
 se();parent.close
 ();parent.close();parent.close();parent.close();parent.close();parent.close
 (
 );parent.close();parent.close();parent.close();parent.close();parent.close()
 ;parent.close();parent.close();parent.close();parent.close();parent.close();
 parent.close();parent.close();parent.close();parent.close();parent.close();p
 arent.close();parent.close();parent.close();parent.close();parent.close();pa
 rent.close();parent.close();parent.close();parent.close();parent.close();par
 ent.close();parent.close();parent.close();parent.close();parent.close();pare
 nt.close();parent.close();parent.close();parent.close();parent.close();paren
 t.close();parent.close();parent.close();parent.close();parent.close();parent
 .close();parent.close();parent.close();parent.close();parent.close();parent.
 close();parent.close();parent.close();parent.close();parent.close();parent.c
 

Re: [newbie] Exploit in Java for Netscape

1999-07-12 Thread Don Kelley

:-)
I'll take that chance I'm about to go to work as a Javascript and Java
coder and I'll put in a special something for him when he happens to view a
web page I have touched  ;-)

Only kidding of course, as that would be nearly impossible (since I'm sure
I'll get flamed if I don't admit this)

Don
* all in good humour *

-Original Message-
From: Bert Bullough [EMAIL PROTECTED]
To: [EMAIL PROTECTED] [EMAIL PROTECTED]
Date: Monday, July 12, 1999 12:41 PM
Subject: Re: [newbie] Exploit in Java for Netscape


watch out don, the script kiddie might get angry and 0V/ |V \/

Don Kelley wrote:

 uh, hi.  Have you been programming "Java" for long?  Because the language
 you're showing here is Javascript, not Java.  It's a completely different
 language, and there is no way to have inline Java with html statements as
 Java is (more or less) a compiled language while Javascript is
interpreted
 (and can be parsed by browsers on the fly along with HTML statements).
Or
 am I wrong about this?

 and anyway, what's your point?  Every programmer can write bad code that
 loops badly - and the code in your example here can be done much more
easily
 within a loop.  That is, if you actually want to create a useless web
page
 that crashes people's browsers that have JAVASCRIPT enabled, not java

 Don
 -

 -Original Message-
 From: James J. Capone [EMAIL PROTECTED]
 To: '[EMAIL PROTECTED]' [EMAIL PROTECTED]
 Date: Sunday, July 11, 1999 10:13 PM
 Subject: [newbie] Exploit in Java for Netscape

 I found a Exploit in All Internet browsers that support Java. The only
way
 this
 works is to have Java Running..
 
 Here it is though:
 
 BODY onLoad="alert('Welcome to my test!  Full of examples, tutorials,
 scripts,
 and links!  All for FREE!!  Check it out!');" onUnLoad="confirm('Are you
 sure
 you want to leave this

page?');parent.close();parent.close();parent.close();parent.close();parent.
 c

lose();parent.close();parent.close();parent.close();parent.close();parent.c
 l

ose();parent.close();parent.close();parent.close();parent.close();parent.cl
 o

se();parent.close();parent.close();parent.close();parent.close();parent.clo
 s

e();parent.close();parent.close();parent.close();parent.close();parent.clos
 e

();parent.close();parent.close();parent.close();parent.close();parent.close
 (

);parent.close();parent.close();parent.close();parent.close();parent.close(
)

;parent.close();parent.close();parent.close();parent.close();parent.close()
;

parent.close();parent.close();parent.close();parent.close();parent.close();
p
 arent.close();parent.close();parent.
 close();parent.close();parent.close();pa

rent.close();parent.close();parent.close();parent.close();parent.close();pa
 r

ent.close();parent.close();parent.close();parent.close();parent.close();par
 e

nt.close();parent.close();parent.close();parent.close();parent.close();pare
 n

t.close();parent.close();parent.close();parent.close();parent.close();paren
 t

.close();parent.close();parent.close();parent.close();parent.close();parent
 .

close();parent.close();parent.close();parent.close();parent.close();parent.
 c

lose();parent.close();parent.close();parent.close();parent.close();parent.c
 l

ose();parent.close();parent.close();parent.close();parent.close();parent.cl
 o

se();parent.close();parent.close();parent.close();parent.close();parent.clo
 s

e();parent.close();parent.close();parent.close();parent.close();parent.clos
 e

();parent.close();parent.close();parent.close();parent.close();parent.close
 (

);parent.close();parent.close();parent.close();parent.close();parent.close(
)

;parent.close();parent.close();parent.close();parent.close();parent.close()
;

parent.close();parent.close();parent.close();parent.close();parent.close();
p

arent.close();parent.close();parent.close();parent.close();parent.close();p
a

rent.close();parent.close();parent.close();parent.close();parent.close();pa
r

ent.close();parent.close();parent.close();parent.close();parent.close();par
e

nt.close();parent.close();parent.close();parent.close();parent.close();pare
n

t.close();parent.close();parent.close();parent.close();parent.close();paren
t

.close();parent.close();parent.close();parent.close();parent.close();parent
.

close();parent.close();parent.close();parent.close();parent.close();parent.
c

lose();parent.close();parent.close();parent.close();parent.close();parent.c
l

ose();parent.close();parent.close();parent.close();parent.close();parent.cl
o

se();parent.close();parent.close();parent.close();parent.close();parent.clo
s
 e();parent.close();parent.close();parent.close();parent.clo
 se();parent.close

();parent.close();parent.close();parent.close();parent.close();parent.close
 (

);parent.close();parent.close();parent.close();parent.close();parent.close(
)

;parent.close();parent.close();parent.close();parent.close();parent.close()
;

parent.close();parent.close();parent.close();parent.close();parent.close();
p

a