<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>Techie Buzz &#187; browser</title> <atom:link href="http://techie-buzz.com/tag/browser/feed" rel="self" type="application/rss+xml" /><link>http://techie-buzz.com</link> <description>Know your technology head on</description> <lastBuildDate>Sat, 26 May 2012 19:50:59 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.2.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/><xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>Opera Browser Vulnerable to Memory Corruption Exploit</title><link>http://techie-buzz.com/opera/opera-browser-vulnerable-to-memory-corruption-exploit.html</link> <comments>http://techie-buzz.com/opera/opera-browser-vulnerable-to-memory-corruption-exploit.html#comments</comments> <pubDate>Mon, 17 Oct 2011 19:28:08 +0000</pubDate> <dc:creator>Simon LR</dc:creator> <category><![CDATA[Online Security]]></category> <category><![CDATA[Opera]]></category> <category><![CDATA[attacker]]></category> <category><![CDATA[browser]]></category> <category><![CDATA[Chrome]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[Firefox]]></category> <category><![CDATA[Hacker]]></category> <category><![CDATA[metasploit]]></category> <category><![CDATA[Online]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[vulnerability]]></category><guid isPermaLink="false">http://techie-buzz.com/?p=63489</guid> <description><![CDATA[Opera browser vulnerable to exploit that could lead to an attacker taking control of your computer.]]></description> <content:encoded><![CDATA[<img src="http://cache.techie-buzz.com/1338085498utwzypco22y5voi3iokgscumbag13380854982mi14hacn5y2cougkta1338085498.png" class="scumbags" /><p>In the raging browser wars, features, security and stability are paramount to competing. Opera might want to get a serious handle on things with the next release they push.</p><p><img class="aligncenter" title="Opera Banner" src="http://cdn2.techie-buzz.com/images4/simon/Opera-Browser.jpg" alt="" width="500" height="333" /></p><p>There is a memory corruption bug that has been present in Opera 10, 11 and the pre-release of 12 on Windows XP SP3. The vulnerability exists within SVG (Scalable Vector Graphics) layout handling. By nesting SVG functions within XML calls, an attacker is able to crash Opera. While crashing a browser might not seem like a huge deal to some, couple it with code injection and you have an exploit that can lead to complete remote code execution, and then it&#8217;s game over.</p><p>The exploit, which was discovered over a year ago, was reported to Opera but never fixed. Jose Vasquez, the original author, has <a href="http://www.exploit-db.com/exploits/17960/">published full details on the vulnerability</a> as well as <a href="http://pastebin.com/SSfhvemZ">written and released a complete Metasploit module</a>. Metasploit is a security framework for penetration testing, allowing a large number of security professional to collaborate on software and service vulnerabilities.</p><p style="text-align: center;"><img class="aligncenter" title="Opera Submit Crash Report" src="http://cdn2.techie-buzz.com/images4/simon/Opera_Crash_Submit2.png" alt="" width="558" height="222" /></p><p>What might seem like a benign crash of your browser, might turn out to be an attacker positioning themselves to take control of your computer and network. Although it&#8217;s <a href="http://techie-buzz.com/tech-news/dep-windows-security-feature-cracked.html">been previously broken</a>, Jose also indicates it may be possible to bypass DEP, which is an active security feature provided by Microsoft,  specifically made to prevent unwanted code execution.</p><p>In an <a href="http://techie-buzz.com/opera/jon-tetzchner-opera-interview.html">interview, Opera&#8217;s co-founder,  Jon Stephenson von Tetzchner</a> indicated their number of users grew from 50 million in 2009 to over 150 million in just one year. There are a lot of users who are potentially vulnerable to exploitation of this bug. When Opera 11.51 was released, <a href="http://techie-buzz.com/browsers/opera-11-51-swordfish-update.html">major security and minor stability issues were the reason for the update</a>. If we consider that  this bug has been present since 10.50, disclosed to Opera over a year ago, and still left unfixed &#8212; many users may want to look at switching to the <a href="http://techie-buzz.com/featured/google-chrome-most-used-browser-techie-buzz.html">very popular Chrome</a>  or <a href="http://techie-buzz.com/tech-news/download-firefox-7-for-desktop-android-released.html">Firefox 7</a>  until Opera fixes this issue.</p> <img src="http://cache.techie-buzz.com/1338085498utwzypco22y5voi3iokgscumbag13380854982mi14hacn5y2cougkta1338085498.png" class="scumbags" /><div style="font-size:12px"> <strong>Share:</strong> <a href="http://techie-buzz.com/opera/opera-browser-vulnerable-to-memory-corruption-exploit.html#commentrespond" rel="bookmark" target="_blank">Comment on This Post</a> | <a href="http://twitter.com/home?source=techiebuzz&status=Opera Browser Vulnerable to Memory Corruption Exploit http%3A%2F%2Fbit.ly%2Foj5Jil via @techiebuzzer" rel="bookmark" target="_blank">Tweet This</a> | <a href="http://www.facebook.com/sharer.php?u=http://techie-buzz.com/opera/opera-browser-vulnerable-to-memory-corruption-exploit.html" rel="bookmark" target="_blank">Share on Facebook</a> | <a href="http://del.icio.us/post?url=http://techie-buzz.com/opera/opera-browser-vulnerable-to-memory-corruption-exploit.html&title=Opera Browser Vulnerable to Memory Corruption Exploit" rel="bookmark" target="_blank">Save to Delicious</a> | <a href="http://www.stumbleupon.com/submit?url=http://techie-buzz.com/opera/opera-browser-vulnerable-to-memory-corruption-exploit.html" rel="bookmark" target="_blank">Stumble This</a> | <a href="http://digg.com/submit?phase=2&url=http://techie-buzz.com/opera/opera-browser-vulnerable-to-memory-corruption-exploit.html&title=Opera Browser Vulnerable to Memory Corruption Exploit" rel="bookmark" target="_blank">Digg This</a> | <a href="http://www.reddit.com/submit?url=http://techie-buzz.com/opera/opera-browser-vulnerable-to-memory-corruption-exploit.html&title=Opera Browser Vulnerable to Memory Corruption Exploit" rel="bookmark" target="_blank">Reddit This</a></div> <br /><div><strong style="font-size:11px;">TAGS:</strong> <span style="text-transform:uppercase;font-size:11px;"><a href="http://techie-buzz.com/tag/attacker" rel="tag">attacker</a>, <a href="http://techie-buzz.com/tag/browser" rel="tag">browser</a>, <a href="http://techie-buzz.com/tag/chrome" rel="tag">Chrome</a>, <a href="http://techie-buzz.com/tag/exploit" rel="tag">exploit</a>, <a href="http://techie-buzz.com/tag/firefox" rel="tag">Firefox</a>, <a href="http://techie-buzz.com/tag/hacker" rel="tag">Hacker</a>, <a href="http://techie-buzz.com/tag/metasploit" rel="tag">metasploit</a>, <a href="http://techie-buzz.com/tag/online" rel="tag">Online</a>, <a href="http://techie-buzz.com/tag/opera" rel="tag">Opera</a>, <a href="http://techie-buzz.com/tag/security" rel="tag">Security</a>, <a href="http://techie-buzz.com/tag/vulnerability" rel="tag">vulnerability</a></span><br/> </small></div><div style="background:#E1E1E1; border: dotted 1px; padding:5px; margin-top:5px;font-size:11px"> <a href="http://techie-buzz.com/opera/opera-browser-vulnerable-to-memory-corruption-exploit.html" title="Opera Browser Vulnerable to Memory Corruption Exploit">Opera Browser Vulnerable to Memory Corruption Exploit</a> originally appeared on <a href="http://techie-buzz.com" title="Techie Buzz">Techie Buzz</a> written by Simon LR on Monday 17th October 2011 03:28:08 PM under <a href="http://techie-buzz.com/category/online-security" title="View all posts in Online Security" rel="category tag">Online Security</a>, <a href="http://techie-buzz.com/category/opera" title="View all posts in Opera" rel="category tag">Opera</a>. Please read the <a href="http://techie-buzz.com/terms-of-use">Terms of Use</a> for fair usage guidance.</div> <br /> ]]></content:encoded> <wfw:commentRss>http://techie-buzz.com/opera/opera-browser-vulnerable-to-memory-corruption-exploit.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>

<!-- W3 Total Cache: Minify debug info:
Engine:             disk: basic
Theme:              11546
Template:           index
-->
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Database Caching 7/21 queries in 0.032 seconds using memcached
Object Caching 687/712 objects using memcached
Content Delivery Network via cdn4.techie-buzz.com

Served from: www.techie-buzz.com @ 2012-05-26 22:24:58 -->

<!-- W3 Total Cache: Page cache debug info:
Engine:             disk: enhanced
Cache key:          tag/browser/feed/_index.xml_gzip
Caching:            enabled
Status:             not cached
Creation Time:      0.219s
Header info:
X-Pingback:         http://techie-buzz.com/xmlrpc.php
Content-Type:       text/xml; charset=UTF-8
Last-Modified:      Sun, 27 May 2012 02:24:58 GMT
Vary:               Accept-Encoding, Cookie
Expires:            Sun, 27 May 2012 02:34:58 GMT
Pragma:             public
Cache-Control:      max-age=600, public, must-revalidate, proxy-revalidate
Etag:               0ddcaa1727b707edea9e9149836c0b5b
X-Powered-By:       W3 Total Cache/0.9.2.4
Content-Encoding:   gzip
-->
