Cute little hole in IE security
Cute little hole in IE security
TITLE
=====
Memory Corruption Vulnerability
DESCRIPTION
===========
Internet Explorer is the flagship browser for the Microsoft Windows OS.
RESEARCHERS
===========
Phuong Nguyen -- phuong at ecqurity . com
David Coomber -- david at ecqurity . com
SUMMARY
=======
Vulnerable Systems:
* Internet Explorer versions 5.x up to SP3 inclusive
* Internet Explorer versions up to 6.1 SP1 inclusive
Immune Systems:
* Internet Explorer version 5 SP4
Tested Platforms:
* Windows 2k, Windows XP
Internet Explorer is vulnerable to numerous security holes, and this one is not that big of a deal, but worth
mentioning. This memory corruption vulnerability allows an attacker to DoS the application itself, no more no less.
An attacker can shutdown Internet Explorer with only 11 bytes.
DETAILS
=======
[Cascading Style Sheet(CSS) Memory Corruption]
There are 1001 ways that an attacker can use to hack, exploit, and crash IE but we believe this is one of the most
compact attacks ever, as an attacker needs only 11 bytes to crash IE. This vulnerability does not give the attacker the
ability to exploit and execute arbitrary code or cause any real damage to the victim, but rather it corrupts the memory space
allocated by IE.
There was a similar vulnerability which has been reported earlier, but this one is more compact.
IE seems to have problems handling Cascading Style Sheet (CSS) elements and therefore an attacker can easily crash IE by using
the following, imho, weird combinations of CSS elements:
<STYLE>@;/*
There you go, 11 bytes is all it takes to crash IE. Having <STYLE>@;/* alone is enough, other HTML tags are not necessary.
If you're too lazy to test this yourself, then we have conveniently created a demonstration page at:
http://www.ecqurity.com/adv/11.html
VENDOR STATUS
=============
This would most likely be small problem to Microsoft and we decided not to report it. Internet Explorer still has quite a few
serious unpatched security holes in it, and we don't think this one deserves Microsoft's attention. In the meantime, perhaps
using a different browser to surf the web is in order.
(data above from http://www.ecqurity.com/adv/IEstyle.html)
=====
Memory Corruption Vulnerability
DESCRIPTION
===========
Internet Explorer is the flagship browser for the Microsoft Windows OS.
RESEARCHERS
===========
Phuong Nguyen -- phuong at ecqurity . com
David Coomber -- david at ecqurity . com
SUMMARY
=======
Vulnerable Systems:
* Internet Explorer versions 5.x up to SP3 inclusive
* Internet Explorer versions up to 6.1 SP1 inclusive
Immune Systems:
* Internet Explorer version 5 SP4
Tested Platforms:
* Windows 2k, Windows XP
Internet Explorer is vulnerable to numerous security holes, and this one is not that big of a deal, but worth
mentioning. This memory corruption vulnerability allows an attacker to DoS the application itself, no more no less.
An attacker can shutdown Internet Explorer with only 11 bytes.
DETAILS
=======
[Cascading Style Sheet(CSS) Memory Corruption]
There are 1001 ways that an attacker can use to hack, exploit, and crash IE but we believe this is one of the most
compact attacks ever, as an attacker needs only 11 bytes to crash IE. This vulnerability does not give the attacker the
ability to exploit and execute arbitrary code or cause any real damage to the victim, but rather it corrupts the memory space
allocated by IE.
There was a similar vulnerability which has been reported earlier, but this one is more compact.
IE seems to have problems handling Cascading Style Sheet (CSS) elements and therefore an attacker can easily crash IE by using
the following, imho, weird combinations of CSS elements:
<STYLE>@;/*
There you go, 11 bytes is all it takes to crash IE. Having <STYLE>@;/* alone is enough, other HTML tags are not necessary.
If you're too lazy to test this yourself, then we have conveniently created a demonstration page at:
http://www.ecqurity.com/adv/11.html
VENDOR STATUS
=============
This would most likely be small problem to Microsoft and we decided not to report it. Internet Explorer still has quite a few
serious unpatched security holes in it, and we don't think this one deserves Microsoft's attention. In the meantime, perhaps
using a different browser to surf the web is in order.
(data above from http://www.ecqurity.com/adv/IEstyle.html)
She Dreams in Digital
\"Led Zeppelin taught an entire generation of young men how to make love, if they just listen\"- Michael Reed(2005)
\"Led Zeppelin taught an entire generation of young men how to make love, if they just listen\"- Michael Reed(2005)
- XunilTlatoani
- Star Farmer
- Posts: 379
- Joined: September 6, 2002, 2:37 pm
- Location: Lakemoor, IL
- Dregor Thule
- Super Poster!
- Posts: 5994
- Joined: July 3, 2002, 8:59 pm
- Gender: Male
- XBL Gamertag: Xathlak
- PSN ID: dregor77
- Location: Oakville, Ontario
- Sylvus
- Super Poster!
- Posts: 7033
- Joined: July 10, 2002, 11:10 am
- Gender: Male
- XBL Gamertag: mp72
- Location: A², MI
- Contact:
this is such a non-issue.
gg on trying to scare people though, i bet you're really engorged now!This vulnerability does not give the attacker the ability to exploit and execute arbitrary code or cause any real damage to the victim, but rather it corrupts the memory space allocated by IE.
"It's like these guys take pride in being ignorant." - Barack Obama
Go Blue!
Go Blue!
- noel
- Super Poster!
- Posts: 10003
- Joined: August 22, 2002, 1:34 am
- Gender: Male
- Location: Calabasas, CA
So wait, let me get this straight. A stylesheet, with text that no legitimate website would ever want to have running (last I checked the whole point of websites was for people to WANT to go to them), will crash my browser? Each and every time? GREAT! That's a spectacular way to keep me from going to that site over and over again.
Oh, my God; I care so little, I almost passed out.
- Akaran_D
- Way too much time!
- Posts: 4151
- Joined: July 3, 2002, 2:38 pm
- Location: Somewhere in my head...
- Contact:
At best it would allow someone to link to a page proclaiming free porn, or something equally inane, and laugh at the clever victims that fall for it every time.
I'm not impressed.
I'll be more impressed when I can get some really fun CSS tricks to work in Firefox and whatnot that only work in IE, such as changing the scrollbar colors.
But that's the price you pay for being a non conformist..
I'm not impressed.
I'll be more impressed when I can get some really fun CSS tricks to work in Firefox and whatnot that only work in IE, such as changing the scrollbar colors.
But that's the price you pay for being a non conformist..
Akaran of Mistmoore, formerly Akaran of Veeshan
I know I'm good at what I do, but I know I'm not the best.
But I guess that on the other hand, I could be like the rest.
I know I'm good at what I do, but I know I'm not the best.
But I guess that on the other hand, I could be like the rest.
- Sylvus
- Super Poster!
- Posts: 7033
- Joined: July 10, 2002, 11:10 am
- Gender: Male
- XBL Gamertag: mp72
- Location: A², MI
- Contact:
Just for shits and giggles, here are the vv stats:
<table border='1' cellpadding='5'><tr><td colspan='3' align='center'>April</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>5956174</td><td>95.7 %</td></tr><tr><td>Netscape</td><td>206435</td><td>3.3 %</td></tr><tr><td>Unknown </td><td>39731</td><td> 0.6 %</td></tr><tr><td>Opera</td><td>11208</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>6220</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>107</td><td> 0%</td></tr><tr><td colspan='3' align='center'>May</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>3977955</td><td>95 %</td></tr><tr><td>Netscape</td><td>157396</td><td>3.7 %</td></tr><tr><td>Unknown </td><td>38712</td><td> 0.9 %</td></tr><tr><td>Opera</td><td>6455</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>5228</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>580</td><td> 0%</td></tr><tr><td colspan='3' align='center'>June</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>3907484</td><td>94.7 %</td></tr><tr><td>Netscape</td><td>158104</td><td>3.8 %</td></tr><tr><td>Unknown </td><td>44859</td><td> 1 %</td></tr><tr><td>Opera</td><td>7312</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>6733</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>196</td><td> 0%</td></tr></table>
IE use is falling, it appears they're in danger of being overtaken!
<table border='1' cellpadding='5'><tr><td colspan='3' align='center'>April</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>5956174</td><td>95.7 %</td></tr><tr><td>Netscape</td><td>206435</td><td>3.3 %</td></tr><tr><td>Unknown </td><td>39731</td><td> 0.6 %</td></tr><tr><td>Opera</td><td>11208</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>6220</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>107</td><td> 0%</td></tr><tr><td colspan='3' align='center'>May</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>3977955</td><td>95 %</td></tr><tr><td>Netscape</td><td>157396</td><td>3.7 %</td></tr><tr><td>Unknown </td><td>38712</td><td> 0.9 %</td></tr><tr><td>Opera</td><td>6455</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>5228</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>580</td><td> 0%</td></tr><tr><td colspan='3' align='center'>June</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>3907484</td><td>94.7 %</td></tr><tr><td>Netscape</td><td>158104</td><td>3.8 %</td></tr><tr><td>Unknown </td><td>44859</td><td> 1 %</td></tr><tr><td>Opera</td><td>7312</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>6733</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>196</td><td> 0%</td></tr></table>
IE use is falling, it appears they're in danger of being overtaken!
"It's like these guys take pride in being ignorant." - Barack Obama
Go Blue!
Go Blue!
Total combined hits have taken a beating over the past 2 months. This may be directly related to the loss of VV points or lack of good flame wars. (or just summer boredom)Sylvus wrote: IE use is falling, it appears they're in danger of being overtaken!
Should Veeshan Vault evolve to "A Gaming community" instead of "An Everquest Community"? All it would take is a quick sweep of some other mesage boards with some strategically placed flames to bring up the total hits count.
Jackass the Globe 2004 Campaign!
Last edited by Winnow on July 27, 2004, 3:28 pm, edited 1 time in total.
- Dregor Thule
- Super Poster!
- Posts: 5994
- Joined: July 3, 2002, 8:59 pm
- Gender: Male
- XBL Gamertag: Xathlak
- PSN ID: dregor77
- Location: Oakville, Ontario
- Kilmoll the Sexy
- Super Poster!
- Posts: 5295
- Joined: July 3, 2002, 3:31 pm
- Gender: Male
- XBL Gamertag: bunkeru2k
- Location: Ohio
You notice Netscape use rising as the new breed of retards joined the board with their AOL and its blazing speeds.....Sylvus wrote:Just for shits and giggles, here are the vv stats:
<table border='1' cellpadding='5'><tr><td colspan='3' align='center'>April</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>5956174</td><td>95.7 %</td></tr><tr><td>Netscape</td><td>206435</td><td>3.3 %</td></tr><tr><td>Unknown </td><td>39731</td><td> 0.6 %</td></tr><tr><td>Opera</td><td>11208</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>6220</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>107</td><td> 0%</td></tr><tr><td colspan='3' align='center'>May</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>3977955</td><td>95 %</td></tr><tr><td>Netscape</td><td>157396</td><td>3.7 %</td></tr><tr><td>Unknown </td><td>38712</td><td> 0.9 %</td></tr><tr><td>Opera</td><td>6455</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>5228</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>580</td><td> 0%</td></tr><tr><td colspan='3' align='center'>June</td></tr><tr><td>Browser</td><td>Hits</td><td>Percent</td></tr><tr><td>MS Internet Explorer</td><td>3907484</td><td>94.7 %</td></tr><tr><td>Netscape</td><td>158104</td><td>3.8 %</td></tr><tr><td>Unknown </td><td>44859</td><td> 1 %</td></tr><tr><td>Opera</td><td>7312</td><td> 0.1 %</td></tr><tr><td>Safari</td><td>6733</td><td> 0.1 %</td></tr><tr><td>Konqueror</td><td>196</td><td> 0%</td></tr></table>
IE use is falling, it appears they're in danger of being overtaken!
Wouldn't all Mozilla browsers (e.g. Firefox) be flagged as Netscape under that breakdown?Kilmoll the Sexy wrote:You notice Netscape use rising as the new breed of retards joined the board with their AOL and its blazing speeds.....
If you go to W3 Schools, you will see that Mozilla use in on the rise (up to 1/6 from 1/25 last year). http://www.w3schools.com/browsers/browsers_stats.asp
[65 Storm Warden] Archeiron Leafstalker (Wood Elf) <Sovereign>RETIRED
- masteen
- Super Poster!
- Posts: 8197
- Joined: July 3, 2002, 12:40 pm
- Gender: Mangina
- Location: Florida
- Contact:
VV gets 5 million hits a month? 

"There is at least as much need to curb the cruel greed and arrogance of part of the world of capital, to curb the cruel greed and violence of part of the world of labor, as to check a cruel and unhealthy militarism in international relationships." -Theodore Roosevelt
- Kilmoll the Sexy
- Super Poster!
- Posts: 5295
- Joined: July 3, 2002, 3:31 pm
- Gender: Male
- XBL Gamertag: bunkeru2k
- Location: Ohio
- noel
- Super Poster!
- Posts: 10003
- Joined: August 22, 2002, 1:34 am
- Gender: Male
- Location: Calabasas, CA
But AOL's default browser is IE... Isn't that veird?
http://www.infotoday.com/newsbreaks/nb030804-1.shtml
http://www.infotoday.com/newsbreaks/nb030804-1.shtml
If I remember correctly, the reason AOL bought Netscape was for their server technology, not their browser.AOL to Drop Netscape
by Sheri R. Lanza
--------------------------------------------------------------------------------
August 4, 2003 — What’s the one thing almost everyone agrees is a necessity? A good Web browser. On July 15, America Online announced its pledge of $2 million to the Mozilla Foundation, a new, independent, nonprofit organization that will continue to promote the development of the Mozilla Web browser. This announcement created quite a stir within the Internet community and heralded a change in the browser landscape.
AOL owns Netscape, the long-established and once leading browser. About the same time it announced the contribution to Mozilla, AOL laid off 10 percent of the Netscape staff (approximately 50 people). In addition, AOL recently signed a 7-year agreement with Microsoft to exclusively offer Microsoft Internet Explorer as its browser.
The rumor mill started soon after. Was Netscape on its way out? Speculation abounded, with the final (unofficial) consensus tolling Netscape’s death knell. Many were convinced that AOL would discontinue its support of Netscape and there would be no further releases or updates to the existing version.
AOL spokesperson Andrew Weinstein assured me that his company would continue to support Netscape. In spite of appearances, Netscape is part of AOL’s multibrand strategy. Weinstein said that the layoffs were part of an “ongoing strategy, matching employees with the company’s strategic priorities.” He also indicated that many of the former workers had already secured employment with the Mozilla Foundation. I was left with the impression that AOL was denying any plans to phase out Netscape.
If the Netscape browser disappeared, it could affect vendors in the information community who in the past have had to optimize their Web products for both Internet Explorer and Netscape—and multiple versions of each in many cases. For example, when Factiva phased out Dow Jones Interactive, the new product, Factiva.com, was optimized for Internet Explorer and not made compatible with Netscape.
Oh, my God; I care so little, I almost passed out.
- Kilmoll the Sexy
- Super Poster!
- Posts: 5295
- Joined: July 3, 2002, 3:31 pm
- Gender: Male
- XBL Gamertag: bunkeru2k
- Location: Ohio