lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
From: ko5 at hush.com (ko5@...h.com)
Subject: internet-explorer: bug or feature?

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

hi!

today i played around a bit with my ie (6.0) to test something and i

found the following behaviour:

when calling a url like

  about:mooh

ie shows me a page with the content 'mooh' and when i call

  about:<script>alert('*plopp*');</script>

a small alert popps up and says me '*plopp*', so it seems, that i can

inject any code i want.

i am not sure if its what the 'about:'-construct is for, but mozilla

doesn't include everything after the ':' in the body of the document.

sry if this was reportet before, but i haven't found something about

this in google or in the archives.

i think its an interesting behaviour ..

btw: about:mozilla seems to be special .. it looks a bit strange ..


ko5
-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.3

wkYEARECAAYFAkBq1kkACgkQn/NqHSmNzSyq1QCfRT3114BilAbYS+PmUIY7Ztke6SQA
oKTK1Raks5IYc1AjMJ8nb1SIYKwV
=9kw/
-----END PGP SIGNATURE-----




Concerned about your privacy? Follow this link to get
FREE encrypted email: https://www.hushmail.com/?l=2

Free, ultra-private instant messaging with Hush Messenger
https://www.hushmail.com/services.php?subloc=messenger&l=434

Promote security and make money with the Hushmail Affiliate Program: 
https://www.hushmail.com/about.php?subloc=affiliate&l=427


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ