Vulnerability Development mailing list archives

RE: true garbage


From: "perkere stinker" <doe_i_sorte_skodder () hotmail com>
Date: Mon, 23 Jul 2001 19:15:49 +0000

moderator: include this if you care, i dont, but other people might have got it wrong too.

uhm i kinda mixed a few things inthere. the urlmon.dll comes from the ms-its: repeated 37 times.. create this link:

<a href=ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:ms-its:.>click this</a> - this will cause the urlmon.dll to crash.

I talked to microsoft about similar issues earlier, and i just gave up. it takes a few weeks, and all you end up with is 'we'll be sure to include a fix in the next product update' - so why waste my time.


From: "Uidam, T (Tim)" <Tim.Uidam () SYD RABOBANK COM>
To: "'perkere stinker'" <doe_i_sorte_skodder () hotmail com>
CC: focus-ms () securityfocus com
Subject: RE: true garbage
Date: Mon, 23 Jul 2001 07:31:44 +0800

IE6 beta (v6.0.2479.0006), and OLXP 6 Beta (same version) on WinNT 4 SP6 are
both vulnerable as well.
After opening the link, it gives the same error message you supplied, then
errors saying "MSOE.DLL could not be inistialised". Nothing about
URLMON.DLL. But naturally, it's version is the same as those shown above.

I find it hard to believe that MS does not care about this issue. Unless
your correspondance was with their security bug tracking team, and not their
regular, non-security bug trackers?

-----Original Message-----
From: perkere stinker [mailto:doe_i_sorte_skodder () hotmail com]
Sent: Monday, 23 July 2001 4:37
To: vuln-dev () securityfocus com
Cc: bugtraq () securityfocus com; focus-ms () securityfocus com
Subject: true garbage





_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp


Current thread: