Crash IE with plain HTML

rh71

No Lifer
Aug 28, 2001
52,844
1,049
126
Only IE ? Don't have my dev machine handy with all the other browsers...
 

http://www.theinquirer.net/?article=9288
Internet Explorer's dumbest bug ever revealed

One line of HTML and it's dead

By Staff at the Newsdesk: Friday 02 May 2003, 18:08

BORED OF CREATING buffer overflow possibilities and security gaps an electronic elephant could walk through, Microsoft's Internet Explorer development team has turned its attention to good old HTML. Thankfully, this bug just crashes IE. Embarrassingly for the Vole, it's done with just one malformed line of HTML.

The bug is listed on BugTraq as requiring five lines of HTML but, after a small amount of experimentation, you'll find that it can be done with just one line of HTML. The offending line?

<input type crash>

In fact, the word "crash" doesn't really make any difference; you can put "calamari" or "IE sucks" in there and it will still go belly up.

So the Vole has definitely managed to outdo itself this time. According to Neowin, Outlook, Frontpage and anything else that uses shlwapi.dll suffers the same fate. So that simple line of malformed HTML could stop you from reading your email too.
 

I just sent myself an email with the code in it and it crashed outlook. This is bad. I guess Microsoft's developers are going to be working today.
 

Adul

Elite Member
Oct 9, 1999
32,999
44
91
danny.tangtam.com
Originally posted by: dwell
I just sent myself an email with the code in it and it crashed outlook. This is bad. I guess Microsoft's developers are going to be working today.

haha damn it works!

AMEESH FIX THIS NOW! :p
 

911paramedic

Diamond Member
Jan 7, 2002
9,448
1
76
That's pretty bad, not too many "common" internet peeps update their IE, this is going to cause problems for a while.
 

Harvey

Administrator<br>Elite Member
Oct 9, 1999
35,059
73
91
Doesn't crash NS 6.23. :)

At Microsoft, failure is not an option -- It's built in. :Q
 

911paramedic

Diamond Member
Jan 7, 2002
9,448
1
76
Originally posted by: Harvey
Doesn't crash NS 6.23. :)

At Microsoft, failure is not an option -- It's built in. :Q
NS? Can you say non-compliant?

NS would be great if they would just comply with standard codes...