Tuesday, October 19, 2004

"IE Shines On Broken Code", says BugTraq Test

Slashdot has a post from timothy where he came across a BugTraq entry on web browser security. Basically, the story is that Michal Zalewski started feeding randomly malformed HTML into Microsoft Internet Explorer, Mozilla, Opera, Lynx, and Links and watching what happened. The bottom line?
"All browsers but Microsoft Internet Explorer kept crashing on a regular basis due to NULL pointer references, memory corruption, buffer overflows, sometimes memory exhaustion; taking several minutes on average to encounter a tag they couldn't parse."
If you want to try this at home, he's also provided the tools he used in the BugTraq entry.

No comments:

Post a Comment