lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <200403311430.i2VEUdMU022862@mailserver2.hushmail.com> From: ko5 at hush.com (ko5@...h.com) Subject: internet-explorer: bug or feature? -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 hi! today i played around a bit with my ie (6.0) to test something and i found the following behaviour: when calling a url like about:mooh ie shows me a page with the content 'mooh' and when i call about:<script>alert('*plopp*');</script> a small alert popps up and says me '*plopp*', so it seems, that i can inject any code i want. i am not sure if its what the 'about:'-construct is for, but mozilla doesn't include everything after the ':' in the body of the document. sry if this was reportet before, but i haven't found something about this in google or in the archives. i think its an interesting behaviour .. btw: about:mozilla seems to be special .. it looks a bit strange .. ko5 -----BEGIN PGP SIGNATURE----- Note: This signature can be verified at https://www.hushtools.com/verify Version: Hush 2.3 wkYEARECAAYFAkBq1kkACgkQn/NqHSmNzSyq1QCfRT3114BilAbYS+PmUIY7Ztke6SQA oKTK1Raks5IYc1AjMJ8nb1SIYKwV =9kw/ -----END PGP SIGNATURE----- Concerned about your privacy? Follow this link to get FREE encrypted email: https://www.hushmail.com/?l=2 Free, ultra-private instant messaging with Hush Messenger https://www.hushmail.com/services.php?subloc=messenger&l=434 Promote security and make money with the Hushmail Affiliate Program: https://www.hushmail.com/about.php?subloc=affiliate&l=427
Powered by blists - more mailing lists