Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: RE: for IE researchers, found a link crashing IE

RE: for IE researchers, found a link crashing IE

From: <ad_at_class101.org>
Date: Tue, 1 Nov 2005 11:05:45 +0100

So in the case of the website go off or remove the webpage, attached is the
saved page also crashing IE while loaded offline. Cheers

Nb: can't attach, size restriction, here is a direct link
http://class101.org/poc.rar

-----Message d'origine-----
De : ad_at_class101.org [mailto:ad_at_class101.org] Envoyé : dimanche 30 octobre
2005 23:50 À : 'Greg'; 'full-disclosure_at_lists.grok.org.uk'
Objet : RE: [Full-disclosure] for IE researchers, found a link crashing IE

.....................

Look my thread here:

http://class101.org/viewtopic.php?p=1272#1272

I recall my tests..

Windows XP Professional SP1 ENGLISH 64-bit (IE32-6.0.3790.1830) -crash-
Windows XP Professional SP1 ENGLISH 64-bit (IE64-6.0.3790.1830) -crash-
Windows XP Professional SP2 ENGLISH 32-bit (IE32-6.0.2900.2180) -nocrash-
Windows XP Professional SP1 ENGLISH 32-bit (IE32-6.0.2900.1106) -crash-
Windows 2k Workstation SP4 ENGLISH 32-bit (IE32-6.0.2800.1106) -crash-
Windows 2k Server SP4 ENGLISH 32-bit (IE32-6.0.2800.1106) -crash- Windows
NT4 Workstation SP6a ENGLISH 32-bit (IE32-6.0.2800.1106) -nocrash- Windows
NT4 Server SP6a ENGLISH 32-bit (IE32-6.0.2800.1106) -nocrash- Windows 2k3
Server Std SP1 ENGLISH 32-bit (IE32-6.0.3790.1830) -crash- => (silently
exiting, no crash box...)

And I don’t think this is fake screenshots

http://class101.org/bug2ksp4.bmp
http://class101.org/bugxpsp1.bmp

-----Message d'origine-----
De : ad_at_class101.org [mailto:ad_at_class101.org]
Envoyé : dimanche 30 octobre 2005 23:50
À : 'Greg'; 'full-disclosure_at_lists.grok.org.uk'
Objet : RE: [Full-disclosure] for IE researchers, found a link crashing IE

.....................

Look my thread here:

http://class101.org/viewtopic.php?p=1272#1272

I recall my tests..

Windows XP Professional SP1 ENGLISH 64-bit (IE32-6.0.3790.1830) -crash-
Windows XP Professional SP1 ENGLISH 64-bit (IE64-6.0.3790.1830) -crash-
Windows XP Professional SP2 ENGLISH 32-bit (IE32-6.0.2900.2180) -nocrash-
Windows XP Professional SP1 ENGLISH 32-bit (IE32-6.0.2900.1106) -crash-
Windows 2k Workstation SP4 ENGLISH 32-bit (IE32-6.0.2800.1106) -crash-
Windows 2k Server SP4 ENGLISH 32-bit (IE32-6.0.2800.1106) -crash-
Windows NT4 Workstation SP6a ENGLISH 32-bit (IE32-6.0.2800.1106) -nocrash-
Windows NT4 Server SP6a ENGLISH 32-bit (IE32-6.0.2800.1106) -nocrash-
Windows 2k3 Server Std SP1 ENGLISH 32-bit (IE32-6.0.3790.1830) -crash- =>
(silently exiting, no crash box...)

And I don’t think this is fake screenshots

http://class101.org/bug2ksp4.bmp
http://class101.org/bugxpsp1.bmp

-----Message d'origine-----
De : full-disclosure-bounces_at_lists.grok.org.uk
[mailto:full-disclosure-bounces_at_lists.grok.org.uk] De la part de Greg
Envoyé : dimanche 30 octobre 2005 21:43
À : full-disclosure_at_lists.grok.org.uk
Objet : Re: [Full-disclosure] for IE researchers, found a link crashing IE

----- Original Message -----
From: <ad_at_class101.org>
To: <full-disclosure_at_lists.grok.org.uk>
Sent: Sunday, October 30, 2005 11:55 PM
Subject: [Full-disclosure] for IE researchers, found a link crashing IE

> This link crashes my fully patched IE on
>

Unsure if this was a real bug-crash report or not but for the heck of it,
tested it from 2 Windows boxes.

1) Win XPSP2 with IE6SP2 all fully patched and running, because I was too
lazy to stop it running, Zone Alarm Pro (yes, I know but I like to do this
for other reasons). No crash.

2) Networked (runs wired through the XP box as above and out of that,
wireless to a router) 98SE machine with IE6SP2 fully patched on it. No
crash.

Was this one an honest report or just someone having a laugh?

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Received on Nov 01 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]