IEBUG: Archives of Internet Explorer ====================================
hi, everyone. i have created a website containing all bugtraq&fd&ms messages related to security issues of: internet explorer, outlook, windows media player and java virtual machine since 2000. it's created and updated by a small piece of php script - updated 3 times per day.
RIGHT HERE: http://iebug.com/ OR http://umbrella.name/iebug.com/display-homepage.php
the Windows OS can only create a limited number of window objects. what will happen if the number of existing windows already reached the limit?
showComfirmationDialog() will return some error code instead of USER_PRESSED_CANCEL, and [install_program] will get
executed.
btw, "writing secure code" http://www.microsoft.com/mspress/books/5957.asp covered a similar case(in that case, it's memory instead of window objects.) that book helped me think on the bug.
i was believing ms at that time. i read those bugtraq messages and reported the authenticode dialog bug to ms in 1 week. the
authenticode dialog bug was harder to reproduce. the download dialog bug AND the authenticode dialog bug have nothing to do
"security zone","download request", "low memory", etc. you can use NOTEPAD windows(the "view-source" protocol) to do the
same thing.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.