lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <200312101658.SAA20392@home.ntrl.net> From: guninski at guninski.com (Georgi Guninski) Subject: RE: FWD: Internet Explorer URL parsing vulnerability On Wed, 10 Dec 2003 16:06:20 +0100 Rainer Gerhards <rgerhards@...adiscon.com> wrote: > Just to add > > http://www.microsoft.com:security%00@....linux.org/ > > works equally well with Mozilla/5.0 (X11; U; Linux i686; en-US; > rv:1.2.1) Gecko/20030225 under Red Hat Linux 9. So it is not just an IE > issue... > On mozilla 1.5 the above does not work. The location bar displays http://www.microsoft.com:security%00@....linux.org/ which seems the expected behavior. On linux more fun seems this: http://www.microsoft.com__________________________________________________________________@....fuckmicrosoft.com/ georgi