Re: [Full-Disclosure] Web browsers - a mini-farce

From: Michal Zalewski (lcamtuf_at_ghettot.org)
Date: 10/20/04

  • Next message: Ronny Adsetts: "Re: [Full-Disclosure] Re: Re: Any update on SSH brute force attempts?"
    To: Martin <nakal@nurfuerspam.de>
    Date: Wed, 20 Oct 2004 10:35:08 +0200 (CEST)
    
    

    On Wed, 20 Oct 2004, Martin wrote:

    > Here, may I make your collection more complete?
    > /.../
    > PS: No, it's not been discovered by your tool. And I reported
    > it already several years ago.

    No you can't, for that very reason. But you are very much advised to
    report it to them and to FD or other lists.

    Gee...

    I reported on a very basic, objective observation. HTML parsers /
    renderers in popular alternative browsers are considerably more fragile
    than in MSIE. Some of them just annoy, and some seem to be exploitable
    under right conditions. That's that. I did not use a dodged tool, I did
    not made up results, it's all open source, and rather well documented. You
    are free to reproduce it.

    I am not a Microsoft-loving, Linux-bashing zealot; if you bother to visit
    by homepage or google around, it will become apparent that I use and enjoy
    Linux, and usually do not touch Windows with a ten foot pole; not because
    of religious beliefs, but simply because I find it not suited well for
    what I do on a daily basis. I did poke fun at Microsoft in the past, too:

      http://lcamtuf.coredump.cx/strikeout/

    For this particular issue, I got numerous confirmations, including new
    submissions from people using Safari, w3m, elvis, Konqueror and so forth,
    so this is not really a localized problem, but rather a sign that
    Microsoft did something others couldn't be bothered to.

    I specifically stated that this does *NOT* prove that MSIE is safer to
    use; there are numerous other factors beside code parsing that count. But
    it indeed casts doubt on the claims of higher security of the alternative
    browsers, suggesting that much of it may turn to be just a result of the
    current status quo.

    A number of people assumes that I say MSIE is better than open source
    browsers; I did not say this, and I do not have any agenda to push. It's
    really disappointing to get so much hate mail when objective results
    suggest one thing, and be well received when they point the other way (at
    Microsoft, Sendmail, etc).

    -- 
    ------------------------- bash$ :(){ :|:&};: --
     Michal Zalewski * [http://lcamtuf.coredump.cx]
        Did you know that clones never use mirrors?
    --------------------------- 2004-10-20 10:24 --
       http://lcamtuf.coredump.cx/photo/current/
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Ronny Adsetts: "Re: [Full-Disclosure] Re: Re: Any update on SSH brute force attempts?"

    Relevant Pages

    • [Full-disclosure] Compromising pictures of Microsoft Internet Explorer!
      ... to report on a casual 30-minute experiment I've conducted of recent. ... You might remember the 'mangleme' affair, where various browsers were ... MSIE performed admirably compared to other browsers (although ... unless code execution path can be affected later on. ...
      (Full-Disclosure)
    • Compromising pictures of Microsoft Internet Explorer!
      ... to report on a casual 30-minute experiment I've conducted of recent. ... You might remember the 'mangleme' affair, where various browsers were ... MSIE performed admirably compared to other browsers (although ... unless code execution path can be affected later on. ...
      (Bugtraq)
    • Re: Server Usage Report
      ... I can't seem to find a Web Usage Logging service? ... Download MPS report tool from: ... Microsoft CSS Online Newsgroup Support ... When opening a new thread via the web interface, we recommend you check ...
      (microsoft.public.windows.server.sbs)
    • Re: Strange SBS errors...
      ... MSSBSSSR.EXE is used to collect Server Status Report and Usage report. ... seems the monitoring component is corrupt. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
      (microsoft.public.windows.server.sbs)
    • Re: Forms or Reports
      ... with Stupid Dashes. ... There are NO references in any book, the Microsoft resourses on the Web ... indicate how data from a Form can be SAVED to a Report. ...
      (microsoft.public.access.forms)