lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <417D2D49.2040406@cornell.edu> From: ecb29 at cornell.edu (Elliott Bäck) Subject: Re: [lists] python does mangleme (with IE bugs!) The URL you give for the crash_IE files simply refresh until they get to http://felinemenace.org/~nd/crash_ie/2447.html and show a 404 error... Thanks, Elliott C. B?ck 607-229-0623 119 Blair St. #2 ------------------------------------------ www.spreadIE.com www.elliottback.com ned wrote: >i've made a port of mangleme: >http://felinemenace.org/~nd/htmler.py >with a few extra quirks (such as file extentions/url types) > >it finds IE bugs after roughly 2.5 -> 3 hours and they are at: >http://felinemenace.org/~nd/crash_ie/ > >They are not the null pointer dereference that Michal found (which >curiously seems to not own my 6.0.2800.1106.xpsp1?) but some other >probably non-exploitable problems! > >htmler.py doesn't use CGI like mangleme but generates webpages in the >directory 'html1' numbered 0.html to n.html. 0.html then uses a refresh to >load 1.html and so on with little user interaction required! > >anyway, if you find bugs with it, don't sell to anyone/notify vendors! >- nd > > >
Powered by blists - more mailing lists