[Full-Disclosure] Re: Internet Explorer and Opera local zone restriction bypass

Valdis.Kletnieks_at_vt.edu
Date: 10/31/03

  • Next message: morning_wood: "Re: [Full-Disclosure] Shortcut...... may cause 100% cpu use!!!"
    To: Thor Larholm <thor@pivx.com>
    Date: Fri, 31 Oct 2003 01:19:15 -0500
    
    
    

    On Thu, 30 Oct 2003 14:30:00 PST, Thor Larholm <thor@pivx.com> said:

    > Flash can remove the first and latter, and there is absolutely no
    > reverse-engineering that will convince IE to render a BAE-64 encoded
    > string as HTML.

    This the same IE that's been known to render a frikking *JPEG* as HTML? ;)

    http://cert.uni-stuttgart.de/archive/bugtraq/2001/02/msg00168.html

    I would have thought that you of all people would know better....

    "absolutely no reverse-engineering". I give it a week. :)

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: morning_wood: "Re: [Full-Disclosure] Shortcut...... may cause 100% cpu use!!!"

    Relevant Pages

    • Re: Postels law
      ... The counter argument for me has always been JPEG. ... HTML is probably the best example to date. ... limited purpose to be a text format wrapper. ... Such acceptance comes in fact ...
      (comp.databases.theory)
    • Re: Paypal without HTML email
      ... > Well the reason I suggested Google mail is because it reads HTML without ... the last thing I want is to be able to render it. ... > Actually it's a complete myth that plain text is somehow more secure than ... formatting in its registration process than you've done in discussing ...
      (uk.people.consumers.ebay)
    • Re: Plain text files in internet explorer
      ... >text/plain to allow the student to read the markup, ... >the hard disk as .html. ... Look how elegantly web servers handle that *specific* ... Photoshop makes a JPEG. ...
      (Vuln-Dev)
    • Re: HTML Formatting in .NET 2.0
      ... > You should be aware, though, that the reason this is used is because XHTML ... > will eventually supercede HTML on the WWW. ... > will eventually cause all browsers to render content in the same way. ... Putting CSS styles into an external style sheet, ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: JPEG attachment to email
      ... Then I sent a fresh JPEG, just a picture of a model car, to my relative, Roger. ... html, which has the same content as the text. ... has been corrupted by a broken email client - but I guess ... Encoded attachments should not be "wrapped" in HTML. ...
      (comp.sys.acorn.misc)