Author Topic: Internet Explorer crash  (Read 3078 times)

0 Members and 1 Guest are viewing this topic.

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Internet Explorer crash
« on: February 15, 2005, 04:25:05 pm »
Thought I'd share it here.  Nothing huge or important, just a little crash:

Quote
hi,

Affected Software : Microsoft Internet Explorer
Vulnerability : Remote DOS / Crash
Tested On : MS IE 6.0 SP1, Win2K SP4, [up-to-date]
according to windowsupdate.com

Discovered by : Gregory R. Panakkal

HomePage : http://www.crapware.tk

Details
=======
Pointing a link to the URI -> file://!:\ [replace !
with the character with ascii value for eg:- 0xA0].
Causes IE6-SP1 to crash, the illegal op occuring in
user32.dll. Other special characters are also
possible.


Demo
====
A demonstration is available at the following URL.

http://crapware.lx.ro/junkcode/security/ie-sp1-file-a0-crash.htm


Greetz to
=========
Rakesh Balasunder - r0ck@iNfy
CK - Saitegog!  :)

rgds,
Gregory R. Panakkal


Offline Warrior

  • supreme mac daddy of trolls
  • Hero Member
  • *****
  • Posts: 7503
  • One for a Dime two for a Quarter!
    • View Profile
Re: Internet Explorer crash
« Reply #1 on: February 15, 2005, 04:47:47 pm »
hahhaha thats great!
One must ask oneself: "do I will trolling to become a universal law?" And then when one realizes "yes, I do will it to be such," one feels completely justified.
-- from Groundwork for the Metaphysics of Trolling

Offline Joe

  • B&
  • x86
  • Hero Member
  • *****
  • Posts: 10319
  • In Soviet Russia, text read you!
    • View Profile
    • Github
Re: Internet Explorer crash
« Reply #2 on: February 15, 2005, 05:04:36 pm »
An IE crash is no longer the exception to the rule. It has become the rule, and the exception is not crashing.
I'd personally do as Joe suggests

You might be right about that, Joe.


Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Re: Internet Explorer crash
« Reply #3 on: February 15, 2005, 06:40:46 pm »
Apparently it's been around (unfixed) for almost a year

Quote
>> Discovered by : Gregory R. Panakkal

Incorrect: E.Kellinis reported it on Friday, May 07, 2004 to bugtraq:
http://www.securityfocus.com/archive/1/362524/2004-05-06/2004-05-12/0


>> Pointing a link to the URI -> file://!:\ [replace !
>> with the character with ascii value for eg:- 0xA0].
>> Causes IE6-SP1 to crash, the illegal op occuring in
>> user32.dll. Other special characters are also
>> possible.


More details can be found here:
http://lists.netsys.com/pipermail/full-disclosure/2004-May/021272.html
http://lists.netsys.com/pipermail/full-disclosure/2004-December/030115.html

                        .-----------------------------------,
                       / Berend-Jan Wever aka SkyLined       )
                      / skylined@edup.tudelft.nl            / \
                     / http://www.edup.tudelft.nl/~bjwever /  /
                    / PGP key ID 0x48479882               /  /
                   / .----.            ,                 /  /
                  / (      '  /       /  .     __   __/ /  /
                 /   `'-._   /.' | / /  / ( / /_.'.' / /  /
                (         ) / )  |/ /  / / ) (__ (__/ /  /
                 \-------' ------` '-----------------<  /
                  \______.`\______\/\_________________\/




Offline sujak

  • Newbie
  • *
  • Posts: 42
  • Sujak@useast
    • View Profile
Re: Internet Explorer crash
« Reply #4 on: February 15, 2005, 11:22:28 pm »
mine didnt crash.......
Next time someone tells you anything is possible, ask them to dribble a football.

Offline Mythix

  • The Dude
  • x86
  • Hero Member
  • *****
  • Posts: 1569
  • Victory
    • View Profile
    • Dark-Wire
Re: Internet Explorer crash
« Reply #5 on: February 16, 2005, 12:24:00 am »
are you on SP1 or SP2?
Philosophy, n. A route of many roads leading from nowhere to nothing.

- Ambrose Bierce


Offline MyndFyre

  • Boticulator Extraordinaire
  • x86
  • Hero Member
  • *****
  • Posts: 4540
  • The wait is over.
    • View Profile
    • JinxBot :: the evolution in boticulation
Re: Internet Explorer crash
« Reply #6 on: February 16, 2005, 11:16:32 am »
Crashed on WinXP SP2 here at school.
I have a programming folder, and I have nothing of value there

Running with Code has a new home!

Our species really annoys me.

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Re: Internet Explorer crash
« Reply #7 on: February 16, 2005, 12:02:16 pm »
Sujak is probably on Mac, which would explain it