lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: lists.netsys.com at jscript.dk (Thor Larholm)
Subject: Internet Explorer 6 DoS Bug

Positively confirmed on 6.0.2800.1106.xpsp2.030422-1633 when entering C:\aux in
the Address Bar.

Seeing as the behavior of this scenario is inconsistent between list subscribers
with the same IE version, one could believe the bug is not in IE but in urlmon
or shellexecute somewhere.


Regards
Thor Larholm
PivX Solutions, LLC - Senior Security Researcher

----- Original Message ----- 
From: <fabian.becker2@...st.de>
To: <full-disclosure@...ts.netsys.com>
Sent: Monday, July 07, 2003 6:25 PM
Subject: [Full-Disclosure] Internet Explorer 6 DoS Bug


> Hi,
> I found a bug in IE6 ?n Windows XP with all Service Packs and Patches
installed:
> If you enter C:\aux in the adressline of the IE (not EXPLORER,
InternetExplorer)
> and hit enter, the window will freeze. This bug is simmilar to C:\con\con
> but not as dagerous. But its the same reason, naimly that windows trys to
> open aux, a hardware device in earlier windows versions.
> I already sended an email to Microsoft but they said the bug wouldn't exist.
>
> Bye
>
> Fabian Becker (www.neonomicus.ionichost.com)
> fabian.becker2@...st.de
>
>
>
>
> ________________________________________
> Mehr Power f?r Ihre eMail - mit den neuen Leistungspaketen bei
http://www.epost.de
>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.netsys.com/full-disclosure-charter.html


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ