Re: [Full-Disclosure] PoC for Internet Explorer >=5.0 buffer overflow (trivial exploit for hard case).

From: morning_wood (se_cur_ityat_private)
Date: Tue Jul 01 2003 - 09:20:17 PDT

  • Next message: Te Smith: "Re: Bypassing ZoneAlarm (limited)"

    ----- Original Message ----- 
    From: "3APA3A" <3APA3Aat_private>
    To: <bugtraqat_private>
    Cc: <full-disclosureat_private>
    Sent: Tuesday, July 01, 2003 4:27 AM
    Subject: [Full-Disclosure] PoC for Internet Explorer >=5.0 buffer
    overflow (trivial exploit for hard case).
    
    confirming...
    
    on WinXP Pro - IE 6
    1. crash ( hang ) when "test2.htm" run from desktop ( local )
    c:\somepath\test2.htm
    2. no crash when run via a webserver ( remote )
    http://exploit.wox.org/test2.htm
    
    on Win2K Pro - IE 5
    1. same result as above
    
    
    it is a local exploit as far as I can tell
    
    morning_wood
    http://exploitlabs.com
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    



    This archive was generated by hypermail 2b30 : Tue Jul 01 2003 - 10:00:26 PDT