Sorry for the delayed response.
I had success in exploiting it remotely by a simple _javascript_
<script>window.open("http://aa...");</script>. But i think it doesnt work with some drivers.I am using XP ,professional, SP2. and firefox 1.0.6. I am using a string of about 53,000 char to overflow the buffer.
Thanks
Sumit
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
