<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Krebs on Security &#187; ms-its</title>
	<atom:link href="http://krebsonsecurity.com/tag/ms-its/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Thu, 09 Feb 2012 22:39:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Another Way to Ditch IE6</title>
		<link>http://krebsonsecurity.com/2010/02/another-way-to-ditch-ie6/</link>
		<comments>http://krebsonsecurity.com/2010/02/another-way-to-ditch-ie6/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 10:55:53 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Latest Warnings]]></category>
		<category><![CDATA[alex holden]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[ie6]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[ms-its]]></category>

		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=787</guid>
		<description><![CDATA[This past week, I was reminded of a conversation I had with an ethical hacker I met at the annual Defcon security conference in Las Vegas, who showed me what may have been (and still remains) the shortest and most elegant trick I've seen to crash Internet Explorer 6 Web browser. I was reminded because the guy who told me about it said it still worked, even though he alerted Microsoft to the flaw back in 2004.]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2010%252F02%252Fanother-way-to-ditch-ie6%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Another%20Way%20to%20Ditch%20IE6%22%20%7D);"></div>
<p>This past week, I was reminded of a conversation I had with an ethical hacker I met at the annual <strong>Defcon</strong> security conference in Las Vegas a couple of years back who showed me what remains the shortest, most elegant and reliable trick I&#8217;ve seen to crash the <strong>Internet Explorer 6</strong> Web browser.</p>
<p>If you&#8217;re curious and have IE6 lying around, type or cut and paste the following into the address bar (that last character is a zero):</p>
<p>ms-its:%F0:</p>
<p>or just click <a href="ms-its:%F0:" target="_self">this link</a> with IE6.</p>
<p>Here&#8217;s a short video example of the crash that results from typing that text above into an IE6 window:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/ulYYtMyaNoc&amp;hl=en&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/ulYYtMyaNoc&amp;hl=en&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><span id="more-787"></span></p>
<p>The &#8220;ms-its&#8221; bit is a reference to one of the helper extensions built into IE6. <strong>Alex Holden</strong>, the Wisconsin based researcher who showed me this crash, said the bug is the result of a <a href="http://goodfellas.shellcode.com.ar/docz/bof/fsp-overflows.txt" target="_blank">pointer overflow</a> in IE. The crash does not appear to work in newer versions of IE.</p>
<p>Holden said he notified Microsoft about his finding back in 2004. An e-mail thread Holden shared with krebsonsecurity.com indicates that Microsoft engineers believed there were no severe security consequences of this bug, and that it would probably be fixed in a future service pack. Obviously, it never was.</p>
<p>One way XP users might encounter this would be if the short code above or something like it were included in a link sent to a targeted user via instant message or e-mail. Indeed, one could imagine a computer worm that went around and changed the victim&#8217;s default home page to this short bit of code. The victim would be no longer be to get online&#8230;.with IE6, anyway (although a registry hack could almost certainly fix the swapped home page).</p>
<p>There is one interesting possible use for this tiny snippet of crash-inducing code. Maybe someone you know and care about insists on using IE6 or refuses to upgrade to IE7 or IE8. Install Firefox or some other browser alternative, and then change their IE home page to &#8220;ms-its:%F0:&#8221; Chances are good they will never be able to open IE6 again.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2010/02/another-way-to-ditch-ie6/feed/</wfw:commentRss>
		<slash:comments>37</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 2/14 queries in 0.005 seconds using memcached
Object Caching 310/328 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-11 11:46:44 -->
