[Full-Disclosure] [IE] Pure html DOS although some version require minor user interaction ( highlighting/minimising )

John mccann at lexicon.net
Sat Oct 18 05:29:13 BST 2003


Basicly this simple employees a HEAP of <big> tags and only requires a 
single closing tag. Someone versions on view will die others require 
something to activate rendering I assume this could be done via a java 
script.

Proof of concept

http://www.lexicon.net/mccann/t.html

Mozilla doesn't crash some version my experience high cpu usage while 
rendering also the layout will be stuffed but it is also a problem with 
overflowing font sizes.
Opera untested.
Other untested.




Full-Disclosure is hosted and sponsored by Secunia.