lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: ecb29 at cornell.edu (Elliott Bäck)
Subject: Re: [lists] python does mangleme (with IE bugs!)

The URL you give for the crash_IE files simply refresh until they get to 
http://felinemenace.org/~nd/crash_ie/2447.html and show a 404 error...

Thanks, 
Elliott C. B?ck

607-229-0623
119 Blair St. #2
------------------------------------------
www.spreadIE.com
www.elliottback.com



ned wrote:

>i've made a port of mangleme:
>http://felinemenace.org/~nd/htmler.py
>with a few extra quirks (such as file extentions/url types)
>
>it finds IE bugs after roughly 2.5 -> 3 hours and they are at:
>http://felinemenace.org/~nd/crash_ie/
>
>They are not the null pointer dereference that Michal found (which 
>curiously seems to not own my 6.0.2800.1106.xpsp1?) but some other 
>probably non-exploitable problems!
>
>htmler.py doesn't use CGI like mangleme but generates webpages in the 
>directory 'html1' numbered 0.html to n.html. 0.html then uses a refresh to 
>load 1.html and so on with little user interaction required!
>
>anyway, if you find bugs with it, don't sell to anyone/notify vendors!
>- nd
>
>  
>


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ