Internet Explorer Vulnerability Exploited Again

Charles Bradshaw

Flashlight Enthusiast
Joined
Sep 14, 2002
Messages
2,495
Location
Mansfield, OH
Re: Internet Explorer Vulnerability Exploited Agai

Microsoft security problems and bugs have been a joke of very long standing, even before Linux became popular. It was a joke to me, and I didn't even know that an OS called Linux even existed!
 

Tomas

Banned
Joined
Jun 19, 2002
Messages
2,128
Location
Seattle, WA area
Jeff,

A brief article in the Register mentions some of the recent problems in MS vs Opera, and here's an earlier news.com.com about something old and similar, 2001.

Then there is this brief writeup of recent MS/Opera difficulty from Opera itself. <==== Best description.

I apologize: This particular time it doesn't seem to have wandered into court, as it was "fixed" when it was made very public. I got carried away in writing my reply. In fact, I'm going back to that post to remove where it mentions 'court' in the footnote.

What's interesting is to take any MS Front Page page and run it through the W3C (or anyone else's) validation suite. Often there are very bizarre, non-standards-compliant little 'twists' in the code. Nothing major, nothing that would get most folks excited, but just enough to fiddle with some other browsers.

(One of their favorites used to be not putting in "quotes" in some of the places where the standards require them, and not putting in (or putting in extra) "space" characters. MSIE was set to 'expect' those tiny 'errors' so that it could and would display MSFP pages perfectly - they mirrored each other.)

Of course, the MS/Opera "problem" referred to above wouldn't show up in a validation of the pages, since what was being done specificly to Opera users only was totally within spec. /ubbthreads/images/graemlins/grin.gif Makes it much harder to find that way. None of the automated checks can find it, it has to be looked at line-by-line and code-by-code to find the one little glitch that messes up the entire page.

In this case a three byte "-30" argument buried in a stylesheet was the whole thing. What was interesting is that it was specifically fed to Opera users only, and in a larger package (with less page information) that took longer to download ... /ubbthreads/images/graemlins/rolleyes.gif

Since the MS antitrust stuff, a lot of this has been cleaned up and is not as bad as it once was, especially with MSFP, but there are still holdovers.

Like MS servers not following standards by starting to load-out pages without an ACK, which MSIE on Windows is designed to expect, but causes other browsers/systems to take two to three times as long to start displaying a page because they have to toss that first clump of code and have it resent. Makes MSIE look super fast. (Yes, there were writeups on that, too, but I'm too lazy to dig.)

I just realized this is getting waaayy off topic for this thread, and could be seen as "MS Bashing" by some even though it's just discussing Microsoft's business practices. I'd toss in a joke I have about that, but ...

So, How 'bout them Cubs!?!! /ubbthreads/images/graemlins/grin.gif

T_sig6.gif
 

Icebreak

Flashlight Enthusiast
Joined
Aug 14, 2002
Messages
4,998
Location
by the river
Thanks, Tomas. Very useful information. The links explained what I wanted to know.

I don't think this is too far off track. I got a warning about IE and got the patch as well as some useful information about caveats in IE.

I don't follow baseball very closely but it looks like the Cubbies are having an historical season.
 

Ratus

Newly Enlightened
Joined
Jan 1, 2003
Messages
138
Location
Miami,FL
Sorry if I sounded a little miffed.

But when a hundred people come to me and say they can't get to google or any other search engine. I start to ask the standard questions (What did you do? When did it start? Did you open an e-mail attachment? Did you change any network settings?).

I get to stay late and fix it.

Ah, the hell that is a small shop.

I was just mad at getting my Friday evening shot to hell. /ubbthreads/images/graemlins/frown.gif
 
Top