Cute little hole in IE security

Support, Discussion, Reviews
Post Reply
User avatar
Kylere
Way too much time!
Way too much time!
Posts: 3354
Joined: July 3, 2002, 6:26 pm
Location: Flint, Michigan

Cute little hole in IE security

Post by Kylere »

TITLE
=====

Memory Corruption Vulnerability

DESCRIPTION
===========

Internet Explorer is the flagship browser for the Microsoft Windows OS.

RESEARCHERS
===========

Phuong Nguyen -- phuong at ecqurity . com
David Coomber -- david at ecqurity . com

SUMMARY
=======

Vulnerable Systems:
* Internet Explorer versions 5.x up to SP3 inclusive
* Internet Explorer versions up to 6.1 SP1 inclusive

Immune Systems:
* Internet Explorer version 5 SP4

Tested Platforms:
* Windows 2k, Windows XP


Internet Explorer is vulnerable to numerous security holes, and this one is not that big of a deal, but worth
mentioning. This memory corruption vulnerability allows an attacker to DoS the application itself, no more no less.
An attacker can shutdown Internet Explorer with only 11 bytes.

DETAILS
=======

[Cascading Style Sheet(CSS) Memory Corruption]

There are 1001 ways that an attacker can use to hack, exploit, and crash IE but we believe this is one of the most
compact attacks ever, as an attacker needs only 11 bytes to crash IE. This vulnerability does not give the attacker the
ability to exploit and execute arbitrary code or cause any real damage to the victim, but rather it corrupts the memory space
allocated by IE.

There was a similar vulnerability which has been reported earlier, but this one is more compact.
IE seems to have problems handling Cascading Style Sheet (CSS) elements and therefore an attacker can easily crash IE by using
the following, imho, weird combinations of CSS elements:

<STYLE>@;/*

There you go, 11 bytes is all it takes to crash IE. Having <STYLE>@;/* alone is enough, other HTML tags are not necessary.
If you're too lazy to test this yourself, then we have conveniently created a demonstration page at:

http://www.ecqurity.com/adv/11.html

VENDOR STATUS
=============

This would most likely be small problem to Microsoft and we decided not to report it. Internet Explorer still has quite a few
serious unpatched security holes in it, and we don't think this one deserves Microsoft's attention. In the meantime, perhaps
using a different browser to surf the web is in order.


(data above from http://www.ecqurity.com/adv/IEstyle.html)
She Dreams in Digital
\"Led Zeppelin taught an entire generation of young men how to make love, if they just listen\"- Michael Reed(2005)
User avatar
Spang
Way too much time!
Way too much time!
Posts: 4862
Joined: September 23, 2003, 10:34 am
Gender: Male
Location: Tennessee

Post by Spang »

would one get a shitload of viruses if they were to click on any of the above links?
Make love, fuck war, peace will save us.
User avatar
XunilTlatoani
Star Farmer
Star Farmer
Posts: 379
Joined: September 6, 2002, 2:37 pm
Location: Lakemoor, IL

Post by XunilTlatoani »

/gasp !!! someone found an insignificant bug in software!! stop the presses..

/sarcasm off

At best this belongs in the Computers forum...
Xunil Tlatoani - Gnome Arch Lich (Retired)
Keepers of the Elements

Tlatoani - Gnome Warlock
Light of Dawn (Lightbringer Server)
User avatar
Animalor
Super Poster!
Super Poster!
Posts: 5902
Joined: July 8, 2002, 12:03 pm
Gender: Male
XBL Gamertag: Anirask
PSN ID: Anirask
Location: Canada

Post by Animalor »

You mean my broswer could crash if I go to a website wrote by *anonymous_scriptkiddie_01*?

OMG!!!!
User avatar
Dregor Thule
Super Poster!
Super Poster!
Posts: 5994
Joined: July 3, 2002, 8:59 pm
Gender: Male
XBL Gamertag: Xathlak
PSN ID: dregor77
Location: Oakville, Ontario

Post by Dregor Thule »

I think Kylere goes around painting scarlet IE's on peoples computers.
Image
User avatar
Sylvus
Super Poster!
Super Poster!
Posts: 7033
Joined: July 10, 2002, 11:10 am
Gender: Male
XBL Gamertag: mp72
Location: A², MI
Contact:

Post by Sylvus »

this is such a non-issue.
This vulnerability does not give the attacker the ability to exploit and execute arbitrary code or cause any real damage to the victim, but rather it corrupts the memory space allocated by IE.
gg on trying to scare people though, i bet you're really engorged now!
"It's like these guys take pride in being ignorant." - Barack Obama

Go Blue!
User avatar
noel
Super Poster!
Super Poster!
Posts: 10003
Joined: August 22, 2002, 1:34 am
Gender: Male
Location: Calabasas, CA

Post by noel »

So wait, let me get this straight. A stylesheet, with text that no legitimate website would ever want to have running (last I checked the whole point of websites was for people to WANT to go to them), will crash my browser? Each and every time? GREAT! That's a spectacular way to keep me from going to that site over and over again.
Oh, my God; I care so little, I almost passed out.
User avatar
Akaran_D
Way too much time!
Way too much time!
Posts: 4151
Joined: July 3, 2002, 2:38 pm
Location: Somewhere in my head...
Contact:

Post by Akaran_D »

At best it would allow someone to link to a page proclaiming free porn, or something equally inane, and laugh at the clever victims that fall for it every time.

I'm not impressed.

I'll be more impressed when I can get some really fun CSS tricks to work in Firefox and whatnot that only work in IE, such as changing the scrollbar colors.

But that's the price you pay for being a non conformist..
Akaran of Mistmoore, formerly Akaran of Veeshan
I know I'm good at what I do, but I know I'm not the best.
But I guess that on the other hand, I could be like the rest.
User avatar
Aslanna
Super Poster!
Super Poster!
Posts: 12475
Joined: July 3, 2002, 12:57 pm

Post by Aslanna »

Internet Explorer is the flagship browser for the Microsoft Windows OS.
I learned something new!
Have You Hugged An Iksar Today?

--
User avatar
Sylvus
Super Poster!
Super Poster!
Posts: 7033
Joined: July 10, 2002, 11:10 am
Gender: Male
XBL Gamertag: mp72
Location: A², MI
Contact:

Post by Sylvus »

Just for shits and giggles, here are the vv stats:


<table border='1' cellpadding='5'><tr><td colspan='3' align='center'>April</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>5956174</td><td>95.7 %</td></tr><tr><td>Netscape</td><td>206435</td><td>3.3 %</td></tr><tr><td>Unknown </td><td>39731</td><td> 0.6 %</td></tr><tr><td>Opera</td><td>11208</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>6220</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>107</td><td> 0%</td></tr><tr><td colspan='3' align='center'>May</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>3977955</td><td>95 %</td></tr><tr><td>Netscape</td><td>157396</td><td>3.7 %</td></tr><tr><td>Unknown </td><td>38712</td><td> 0.9 %</td></tr><tr><td>Opera</td><td>6455</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>5228</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>580</td><td> 0%</td></tr><tr><td colspan='3' align='center'>June</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>3907484</td><td>94.7 %</td></tr><tr><td>Netscape</td><td>158104</td><td>3.8 %</td></tr><tr><td>Unknown </td><td>44859</td><td> 1 %</td></tr><tr><td>Opera</td><td>7312</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>6733</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>196</td><td> 0%</td></tr></table>

IE use is falling, it appears they're in danger of being overtaken!
"It's like these guys take pride in being ignorant." - Barack Obama

Go Blue!
User avatar
Winnow
Super Poster!
Super Poster!
Posts: 27712
Joined: July 5, 2002, 1:56 pm
Location: A Special Place in Hell

Post by Winnow »

Sylvus wrote: IE use is falling, it appears they're in danger of being overtaken!
Total combined hits have taken a beating over the past 2 months. This may be directly related to the loss of VV points or lack of good flame wars. (or just summer boredom)

Should Veeshan Vault evolve to "A Gaming community" instead of "An Everquest Community"? All it would take is a quick sweep of some other mesage boards with some strategically placed flames to bring up the total hits count.

Jackass the Globe 2004 Campaign!
Last edited by Winnow on July 27, 2004, 3:28 pm, edited 1 time in total.
User avatar
Sylvus
Super Poster!
Super Poster!
Posts: 7033
Joined: July 10, 2002, 11:10 am
Gender: Male
XBL Gamertag: mp72
Location: A², MI
Contact:

Post by Sylvus »

No, I could have gone farther back and you'd see that April's increase in hits is a spike caused by FF and the pictures that came as a result.
"It's like these guys take pride in being ignorant." - Barack Obama

Go Blue!
User avatar
Dregor Thule
Super Poster!
Super Poster!
Posts: 5994
Joined: July 3, 2002, 8:59 pm
Gender: Male
XBL Gamertag: Xathlak
PSN ID: dregor77
Location: Oakville, Ontario

Post by Dregor Thule »

Keep in mind that 75% of those Unknowns are Kylere spam refreshing his threads.
Image
User avatar
Truant
Way too much time!
Way too much time!
Posts: 4440
Joined: July 4, 2002, 12:37 am
Location: Trumania
Contact:

Post by Truant »

omg i was so scared I downloaded Avant as fast as I could.
User avatar
Ransure
Way too much time!
Way too much time!
Posts: 1262
Joined: July 3, 2002, 2:22 pm
Contact:

Post by Ransure »

Damnit Tru, that was my response.....
This 2cp has been brought to you by DOKURANGER!
User avatar
Kilmoll the Sexy
Super Poster!
Super Poster!
Posts: 5295
Joined: July 3, 2002, 3:31 pm
Gender: Male
XBL Gamertag: bunkeru2k
Location: Ohio

Post by Kilmoll the Sexy »

Sylvus wrote:Just for shits and giggles, here are the vv stats:


<table border='1' cellpadding='5'><tr><td colspan='3' align='center'>April</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>5956174</td><td>95.7 %</td></tr><tr><td>Netscape</td><td>206435</td><td>3.3 %</td></tr><tr><td>Unknown </td><td>39731</td><td> 0.6 %</td></tr><tr><td>Opera</td><td>11208</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>6220</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>107</td><td> 0%</td></tr><tr><td colspan='3' align='center'>May</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>3977955</td><td>95 %</td></tr><tr><td>Netscape</td><td>157396</td><td>3.7 %</td></tr><tr><td>Unknown </td><td>38712</td><td> 0.9 %</td></tr><tr><td>Opera</td><td>6455</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>5228</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>580</td><td> 0%</td></tr><tr><td colspan='3' align='center'>June</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>3907484</td><td>94.7 %</td></tr><tr><td>Netscape</td><td>158104</td><td>3.8 %</td></tr><tr><td>Unknown </td><td>44859</td><td> 1 %</td></tr><tr><td>Opera</td><td>7312</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>6733</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>196</td><td> 0%</td></tr></table>

IE use is falling, it appears they're in danger of being overtaken!
You notice Netscape use rising as the new breed of retards joined the board with their AOL and its blazing speeds.....
User avatar
archeiron
Way too much time!
Way too much time!
Posts: 1289
Joined: April 14, 2003, 5:39 am

Post by archeiron »

Kilmoll the Sexy wrote:You notice Netscape use rising as the new breed of retards joined the board with their AOL and its blazing speeds.....
Wouldn't all Mozilla browsers (e.g. Firefox) be flagged as Netscape under that breakdown?

If you go to W3 Schools, you will see that Mozilla use in on the rise (up to 1/6 from 1/25 last year). http://www.w3schools.com/browsers/browsers_stats.asp
[65 Storm Warden] Archeiron Leafstalker (Wood Elf) <Sovereign>RETIRED
User avatar
noel
Super Poster!
Super Poster!
Posts: 10003
Joined: August 22, 2002, 1:34 am
Gender: Male
Location: Calabasas, CA

Post by noel »

Also, correct me if I'm wrong, but I believe the default browser for AOL is currently a version of Internet Explorer. Not being an AOL user myself, I'm not certain.
Oh, my God; I care so little, I almost passed out.
User avatar
masteen
Super Poster!
Super Poster!
Posts: 8197
Joined: July 3, 2002, 12:40 pm
Gender: Mangina
Location: Florida
Contact:

Post by masteen »

VV gets 5 million hits a month? :shock:
"There is at least as much need to curb the cruel greed and arrogance of part of the world of capital, to curb the cruel greed and violence of part of the world of labor, as to check a cruel and unhealthy militarism in international relationships." -Theodore Roosevelt
User avatar
Kilmoll the Sexy
Super Poster!
Super Poster!
Posts: 5295
Joined: July 3, 2002, 3:31 pm
Gender: Male
XBL Gamertag: bunkeru2k
Location: Ohio

Post by Kilmoll the Sexy »

AOL bought Netscrape in 1999.
User avatar
noel
Super Poster!
Super Poster!
Posts: 10003
Joined: August 22, 2002, 1:34 am
Gender: Male
Location: Calabasas, CA

Post by noel »

But AOL's default browser is IE... Isn't that veird?

http://www.infotoday.com/newsbreaks/nb030804-1.shtml
AOL to Drop Netscape
by Sheri R. Lanza

--------------------------------------------------------------------------------
August 4, 2003 — What’s the one thing almost everyone agrees is a necessity? A good Web browser. On July 15, America Online announced its pledge of $2 million to the Mozilla Foundation, a new, independent, nonprofit organization that will continue to promote the development of the Mozilla Web browser. This announcement created quite a stir within the Internet community and heralded a change in the browser landscape.
AOL owns Netscape, the long-established and once leading browser. About the same time it announced the contribution to Mozilla, AOL laid off 10 percent of the Netscape staff (approximately 50 people). In addition, AOL recently signed a 7-year agreement with Microsoft to exclusively offer Microsoft Internet Explorer as its browser.

The rumor mill started soon after. Was Netscape on its way out? Speculation abounded, with the final (unofficial) consensus tolling Netscape’s death knell. Many were convinced that AOL would discontinue its support of Netscape and there would be no further releases or updates to the existing version.

AOL spokesperson Andrew Weinstein assured me that his company would continue to support Netscape. In spite of appearances, Netscape is part of AOL’s multibrand strategy. Weinstein said that the layoffs were part of an “ongoing strategy, matching employees with the company’s strategic priorities.” He also indicated that many of the former workers had already secured employment with the Mozilla Foundation. I was left with the impression that AOL was denying any plans to phase out Netscape.

If the Netscape browser disappeared, it could affect vendors in the information community who in the past have had to optimize their Web products for both Internet Explorer and Netscape—and multiple versions of each in many cases. For example, when Factiva phased out Dow Jones Interactive, the new product, Factiva.com, was optimized for Internet Explorer and not made compatible with Netscape.
If I remember correctly, the reason AOL bought Netscape was for their server technology, not their browser.
Oh, my God; I care so little, I almost passed out.
User avatar
Kilmoll the Sexy
Super Poster!
Super Poster!
Posts: 5295
Joined: July 3, 2002, 3:31 pm
Gender: Male
XBL Gamertag: bunkeru2k
Location: Ohio

Post by Kilmoll the Sexy »

If that isn't completely retarded. No wonder that worthless piece of shit company keeps cutting payroll for the Braves! They need it to waste on stupid shit.
User avatar
noel
Super Poster!
Super Poster!
Posts: 10003
Joined: August 22, 2002, 1:34 am
Gender: Male
Location: Calabasas, CA

Post by noel »

Consider this...

We're also talking about the company that develops AIM, and owns ICQ as well.
Oh, my God; I care so little, I almost passed out.
Post Reply