Re: MSIE crash-"feature"

From: Remington Winters (fyreguyat_private)
Date: Thu Apr 24 2003 - 13:45:02 PDT

  • Next message: descript: "s0h: Remote/Local exploit and patch for regedit.exe."

    What gif? All it was for me was a non declared form.  IE cant parse
    non-declared forms....not exactly earth shaking though.
    ----- Original Message -----
    From: "Richard Pachito" <alpyhaat_private>
    To: <vuln-devat_private>
    Sent: Wednesday, April 23, 2003 6:41 PM
    Subject: Re: MSIE crash-"feature"
    
    
    > I  think it's pretty interesting how you can crash IE using that gif, but
    > not explorer when it goes to preview.  I thought it rendered the html
    using
    > IE?
    >
    > ----- Original Message -----
    > From: "Magnus Bodin" <magnusat_private>
    > To: <vuln-devat_private>
    > Sent: Wednesday, April 23, 2003 1:35 AM
    > Subject: MSIE crash-"feature"
    >
    >
    > >
    > > Sorry if this is old news already, but IE has a rather interesting
    feature
    > > (tested with 6.0.2600.0000 whatever that means)
    > >
    > > It crashes on very minimalistic code; check here:
    > >
    > >     http://x42.com/test/ie_feature.html
    > >
    > > It can be further stripped down and even sent as different MIME-type
    (see
    > old
    > > posting about the MIME-"smartness in IE):
    > >
    > >     http://x42.com/test/galopp.gif
    > >
    > >
    > > For those who want to test it with their HTML-compatible mail reader,
    send
    > > a mail to
    > >
    > >     iecrashat_private
    > >
    > > and you will get a HTML-mail in return.
    > >
    > > /magnus
    > >
    > > --
    > > http://x42.com
    >
    



    This archive was generated by hypermail 2b30 : Mon Apr 28 2003 - 16:14:41 PDT