IEBUG: Archives of Internet Explorer

From: Liu Die Yu (liudieyuinchina_at_yahoo.com.cn)
Date: 05/26/04

  • Next message: idlabs-advisories_at_idefense.com: "[Full-Disclosure] iDEFENSE Security Advisory 05.26.04: 3Com OfficeConnect Remote 812 ADSL Router Telnet Protocol Denial of Service Vulnerability"
    Date: Tue, 25 May 2004 19:56:53 -0700 (PDT)
    To: BugTraq at SECURITYFOCUS <bugtraq@securityfocus.com>
    
    

    IEBUG: Archives of Internet Explorer
    ====================================

    hi, everyone. i have created a website containing all bugtraq&fd&ms messages related to security
    issues of:
    internet explorer, outlook, windows media player and java virtual machine
    since 2000.
    it's created and updated by a small piece of php script - updated 3 times per day.

    RIGHT HERE:
    http://iebug.com/
    OR
    http://umbrella.name/iebug.com/display-homepage.php

    while reading the messages, i found there is something unclear about some past issues:
    -----
    Vulnerability in Authenticode Verification Could Allow Remote Code Execution (823182)
    http://umbrella.name/iebug.com/display-singlemessage.php?readmsg:mssec_message-20030041
    -----
    Bugtraq: Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! [CRITICAL]
    http://umbrella.name/iebug.com/display-singlemessage.php?readmsg:bugtraq_message-2003050101
    -----
    Bugtraq: Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! - UPDATED
    http://umbrella.name/iebug.com/display-singlemessage.php?readmsg:bugtraq_message-2003050157
    -----
    Bugtraq: Re: Flooding Internet Explorer 6.0.2800 (6.x?) security zones ! - UPDATED
    http://umbrella.name/iebug.com/display-singlemessage.php?readmsg:bugtraq_message-2003050179
    -----

    i put these old messages here because the problem was not explained well, and most importantly,
    other modules may also be

    vulnerable.

    check all messages above and then read on.

    consider the following C code:

    -----
    [read_program_details]
    if(showComfirmationDialog()==USER_PRESSED_CANCEL)
            return FALSE;
    [install_program]
    -----

    anything wrong with the above code?

    the Windows OS can only create a limited number of window objects.
    what will happen if the number of existing windows already reached the limit?

    showComfirmationDialog() will return some error code instead of USER_PRESSED_CANCEL, and
    [install_program] will get

    executed.

    btw, "writing secure code"
    http://www.microsoft.com/mspress/books/5957.asp
    covered a similar case(in that case, it's memory instead of window objects.)
    that book helped me think on the bug.

    i was believing ms at that time. i read those bugtraq messages and reported the authenticode
    dialog bug to ms in 1 week. the

    authenticode dialog bug was harder to reproduce. the download dialog bug AND the authenticode
    dialog bug have nothing to do

    "security zone","download request", "low memory", etc. you can use NOTEPAD windows(the
    "view-source" protocol) to do the

    same thing.

            
                    
    __________________________________
    Do you Yahoo!?
    Friends. Fun. Try the all-new Yahoo! Messenger.
    http://messenger.yahoo.com/


  • Next message: idlabs-advisories_at_idefense.com: "[Full-Disclosure] iDEFENSE Security Advisory 05.26.04: 3Com OfficeConnect Remote 812 ADSL Router Telnet Protocol Denial of Service Vulnerability"

    Relevant Pages

    • Re: Why RosAsm Breaks on a large number of symbols
      ... > Windows message loop is a good starting point. ... But of course this is not a genuine bug report, ... > preservation convention for Windows programing, ... You need to preserve register in callbacks - that's the only _rule_ about ...
      (alt.lang.asm)
    • Re: bad experience with Suse 9.1 on Inspiron 8200
      ... > it is an M$ bug, such technicalities are irrelevant to the end user. ... :-) Windows has ... work as long as they work, trying to install a nitrous ... Linux are at least a *little* bit curious about how their computer works ...
      (alt.os.linux.suse)
    • I think I have been hijacked.
      ... I am running windows xp on my Compaq Presario and Toshiba laptop, ... An internet connection appears to have been added through a USB. ... R - Registry, StartPage/SearchPage changes ... Fixed crashing bug on certain Win2000 and WinXP systems at O23 listing ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Given Up on Linux1
      ... Once I had done enough work and investigated the existing bug reports on ... > dealt with thousands of computers, you should be lucky I'm even ... newbie to Linux. ... But there had not been a windows problem in 12 years I ...
      (alt.os.linux)
    • Re: WMP 11 Recently Added function...
      ... I could quote Zach's statement about how terribly expensive a single bug fix is and how the right thing to do when a bug is identified is not always to fix it. ... Or I could tell you that he has often said that the only way to report a bug in Windows Media Player is to call product support. ... experience of wmp not showing recently added files and the id tags problem with dpoweramp, ...
      (microsoft.public.windowsmedia.player)