Re: [Full-Disclosure] Re: Internet Explorer URL parsing vulnerability

From: Georgi Guninski (guninski_at_guninski.com)
Date: 12/13/03

  • Next message: S G Masood: "RE: [Full-Disclosure] Re: Internet Explorer URL parsing vulnerability"
    To: S G Masood <sgmasood@yahoo.com>
    Date: Sat, 13 Dec 2003 01:06:46 +0200
    
    

    On Fri, 12 Dec 2003 11:01:24 -0800 (PST)
    S G Masood <sgmasood@yahoo.com> wrote:

    >
    > Hello,
    >
    > I was expecting that someone would come up with an
    > explanation as to why the 0x01 trick works. 0x00,
    > 0x0A, 0x0D causing problems would be understandable
    > but, 0x01 causing problems is somewhat strange. This
    > is not the first time IE has a problem with the 0x01
    > byte embedded in the URL:
    >
    > [1]http://www.guninski.com/read.html
    > [2]http://www.guninski.com/scrauto.html
    >
    > Since he discovered these previous issues, maybe
    > Guninski has an explanation.
    >

    yes, m$ have had more serious problems with %01 in the past.

    my explanation is that they just suffer from brain damage and greediness.

    georgi

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: S G Masood: "RE: [Full-Disclosure] Re: Internet Explorer URL parsing vulnerability"

    Relevant Pages

    • Re: [Full-Disclosure] Re: Internet Explorer URL parsing vulnerability
      ... I was expecting that someone would come up with an ... explanation as to why the 0x01 trick works. ... 0x01 causing problems is somewhat strange. ... Guninski has an explanation. ...
      (Full-Disclosure)
    • Has my site been cracked?
      ... meant that the update could not have been the culprit. ... (That would have been strange anyway, although it would have been an ... POSSIBLE BREAK-IN ATTEMPT! ...
      (alt.os.linux.suse)
    • Re: Arsenalfans: Liverpools supposed atmoshphere: A myth
      ... Google Beta User presented the following explanation: ... that in Europe, we may end games cautiously, but if they're expecting ... to set up shop in our half because we'll be hiding, ...
      (uk.sport.football.clubs.liverpool)
    • Re: Psychokinesis??
      ... This one looks strange.. ... Sure, I have an explanation. ... the glass stops moving. ... Something looking pretty strange in a video isn't a reason ...
      (talk.origins)
    • Re: Problem with named range as VBA macro parameter
      ... > expecting us to work it out from a brief explanation. ... IOW, instead of passing the ...
      (microsoft.public.excel.programming)