Internet Explorer Interpreter Stack Overflow
31-05-2006, 10:49
|
#1
|
|
Karateka
Join Date: Dec 2003
Age: 33
Posts: 7,098
|
Internet Explorer Interpreter Stack Overflow
Oops
<html>
<input type="button" name="btn" onclick="document.all['btn'].onclick(0);document.write('');">
</html>
__________________
Quidquid latine dictum sit, altum sonatur.
|
|
|
31-05-2006, 12:47
|
#2
|
|
while(!naked){--clothes}
Join Date: Mar 2004
Location: Glasgow, Scotland
Services: anything for a new job
Posts: 4,100
|
Re: Internet Explorer Interpreter Stack Overflow
but what does this actually do apart from crash IE.
and nothing happens on FF either.....
so what is the point in having a test like this, as most websites will be written correctly anyway.
I just don't understand.
ik
__________________
Let me guess, you picked out yet another colorful box with a crank that I'm expected to turn and turn until OOP! big shock, a jack pops out and you laugh and the kids laugh and the dog laughs and I die a little inside.
|
|
|
31-05-2006, 14:36
|
#3
|
Join Date: Mar 2006
Location: Oslo, Norway.
Services: Get.no 26Mb/3Mb Cable
Posts: 6,559
|
Re: Internet Explorer Interpreter Stack Overflow
Hehe, i like it :p
Nice to know it's so easy to crash a browser...
__________________
Intel C2D E8400@4Ghz (52c) | 2Gb HyperX RAM | nVidia 8800GT 512Mb (700/1000) | Corsair VX550w PSU | Gigabyte EP35-DS3R | Win XP SP3 | 500Gb Seagate Barracuda 7200.11
|
|
|
31-05-2006, 15:08
|
#4
|
|
cf.geek
Join Date: Mar 2005
Posts: 515
|
Re: Internet Explorer Interpreter Stack Overflow
I'm being a bit of a killjoy here, I know, but publishing code that purposefully crashes a piece of software/computer could contravene the UK Misuse of Computers Act 1990 and the person who contravenes this act could face 6 months imprisonment and a fine. I'm not a lawyer, but I have been studying this law for a bit this week due to something I have to do for my job, so be careful.
__________________
"Work and pray, live on hay, You'll get pie in the sky when you die." - Joe Hill
|
|
|
31-05-2006, 15:18
|
#5
|
|
Cable Forum Team
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,477
|
Re: Internet Explorer Interpreter Stack Overflow
Gareth, it would probably work better if the forum didn't block HTML..
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.
"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
|
|
|
31-05-2006, 17:09
|
#6
|
|
Karateka
Join Date: Dec 2003
Age: 33
Posts: 7,098
|
Re: Internet Explorer Interpreter Stack Overflow
Quote:
|
Originally Posted by Stuart C
Gareth, it would probably work better if the forum didn't block HTML..
|
Nope, that was intentional... I only wanted to post the proof of concept, I didn't want to crash peoples' browsers
Although I can do that, if you want
---------- Post added at 17:04 ---------- Previous post was at 17:01 ----------
Quote:
|
Originally Posted by ikthius
but what does this actually do apart from crash IE.
and nothing happens on FF either.....
so what is the point in having a test like this, as most websites will be written correctly anyway.
I just don't understand.
ik
|
It's a stack overflow... it kills the browser as soon as you click the bog-standard html form button that is displayed. Admittedly, it's only a stack overflow and not a buffer overflow, so the consequences aren't as bad. The flaw is there, however, for all to see - and it's not exactly rocket science.
---------- Post added at 17:09 ---------- Previous post was at 17:04 ----------
Quote:
|
Originally Posted by grubbymitts
I'm being a bit of a killjoy here, I know, but publishing code that purposefully crashes a piece of software/computer could contravene the UK Misuse of Computers Act 1990 and the person who contravenes this act could face 6 months imprisonment and a fine. I'm not a lawyer, but I have been studying this law for a bit this week due to something I have to do for my job, so be careful.
|
No worries, mate... I do this for my job too. I'm in IT Security for a major high street financial organisation... incidentally we work a lot with MS and NISCC amongst others.
Although you're right that the law is not clear-cut as to what constitutes a breach of the CA, I'm not worried about posting a PoC
__________________
Quidquid latine dictum sit, altum sonatur.
|
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 02:27.
|