IE Crash bug. This one's tiny, too!

OT: anything goes!

Moderator: Edi

Post Reply
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

IE Crash bug. This one's tiny, too!

Post by Einhander Sn0m4n »

HTML Render Crashes Idiot Exploiter! <==Slashdot Link

Source Code for the Crashy Thing:

Code: Select all

< html >
< form >
< input type crash >
< /form >
< /html >
Stupid, ain't it?

(spaces between the < and >s just in case by the grace of that Yahweh idiot everyone's M$IE tries to render it despite the <code> tags.

*rails Bill Fucking Gates in the FUCKING FOOT!!*
Image Image
User avatar
Admiral Valdemar
Outside Context Problem
Posts: 31572
Joined: 2002-07-04 07:17pm
Location: UK

Post by Admiral Valdemar »

Did I read that right? That thing crashes IE?!
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22640
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Post by Dalton »

Confirmed here. Wow.
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
User avatar
Durandal
Bile-Driven Hate Machine
Posts: 17927
Joined: 2002-07-03 06:26pm
Location: Silicon Valley, CA
Contact:

Post by Durandal »

It's probably just debugging code that was left in there by the programmers when they wanted to test crash-recovery stuff. They just forgot to take it out.
Damien Sorresso

"Ever see what them computa bitchez do to numbas? It ain't natural. Numbas ain't supposed to be code, they supposed to quantify shit."
- The Onion
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

BTW is it against policy to publish source code for IE Crash 'Sploits?
Image Image
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

That's not source code, that's a chunk of HTML.

HTML crashing browsers is nothing new. NS4 in particular was infamous for this, and Mozilla is not immune to this. Furthermore, this seems intentional on the part of Microsoft (though accidentially left in place).

At any rate, you could have posted a link with substance, like the actual BugTraq notice.
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

As I recall, this bug was old news back in 2000.

For that matter, there was also the img=C:\CON\CON exploit for any old Windows 9x box... caused an instant bluescreen.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
Post Reply