Re: rare bug in Opera 9.20 browser

看板Bugtraq作者時間18年前 (2007/07/24 11:06), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/2 (看更多)
This message is in MIME format. The first part should be readable text, while the remaining parts are likely unreadable without MIME-aware tools. --1867909832-2108358546-1185075919=:25560 Content-Type: TEXT/PLAIN; charset=ISO-8859-2 Content-Transfer-Encoding: QUOTED-PRINTABLE On Thu, 18 Jul 2007, jplopezy@gmail.com.ar wrote: :] In this opportunity I go to you with the purpose of communicating a stra= nge fault to them that finds in operates. It consists of creating a documen= t in HTML and in beating a chain of characters $/=93(dollar, sweeps, comile= ) in hexadecimal serian (24 2F 22) this promouth that when trying to see th= e source code when lowering the bar to visualize the end of the east docume= nt promouth that the navigator fails I leave a test of concept down=20 :]=20 Its not exactly but some similars to "opera null byte display": http://sla.ckers.org/forum/read.php?2,11896,11941#msg-11941 " I've just noticed this, when you use Opera internal Source code viewer, it= =20 fails to display the whole html code if the page contains a NULL (0x00)=20 char. Its not a big deal, but it can be abussed to hide evil javascript=20 code for Opera users. I've just tested this in Opera for Windows. :] :] I= =20 leave a test of concept down :] " On Linux it works too... What is interesting, Opera fix this few months ago and now they again=20 add this "future" to the software ;] Kanedaaa --=20 [][][][][][][][][][][][][][][][][][][][][][][][][][][][][][][][][][][][].. [+] You can take our lives,but you will never take our Freedom - W.Wallace [+] Peace on earth depends on the peace in the peoples hearts - Dalai Lama [+] Revolution the only solution - System of a down... [+] Dalej idac dalej dojdziesz dalej siedzac dalej siedzisz - etoe aka ok0 [-] Kanedaaa... Bohateur... Cucumber Team Member... kaneda@bohater.net --1867909832-2108358546-1185075919=:25560--
文章代碼(AID): #16fMob00 (Bugtraq)
文章代碼(AID): #16fMob00 (Bugtraq)