Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Bugtraq: Unknown IE bug with css-styles

Unknown IE bug with css-styles

From: <henkie_is_leet_at_hotmail.com>
Date: 18 May 2004 17:11:49 -0000
('binary' encoding is not supported, stored as-is) Heya ppl!,

I was coding around a bit..
When I was testing the html code with internet explorer, the damn thing started to crash! (Including all other IE's that where open at the same time)

I’ve tested it several times (on different machines) and all had the same problem.

it has something to do with the loading of the css styles from a file in a <table>

it doesn't seem to be exploitable..

---------------------------------------------------------
Access violation in module mshtml.dll occurs at address:
 6364E832 8B01 MOV EAX,DWORD PTR DS:[ECX]
EAX = 0;
---------------------------------------------------------

[Tested on]:
 - Microsoft Windows XP "Home edition" including Service pack 1
 - Microsoft Internet Explorer 6.0.2800.1106.xpsp2.030422-1633
   Updates: Q822925, Q330994, Q824145, Q837009, Q832894

[Sample exploit:]
 - http://www.zeepost.nl/~henkie/index.html

---------------------------------------------------------
Greetings go out to tozzke (sorry m8;))
henkie_is_leet_at_hotmail.com
Received on May 18 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]