Killing web browsers - part II
[Posted October 27, 2004 by corbet]
Last week's discussion on
crashing web browsers with random input noted that, of all the browsers
tested, only Internet Explorer survived. Since then, Michal Zalewski has
posted
a followup stating that, eventually,
IE fell over as well. So, as Mr. Zalewski put it:
This means that VIRTUALLY EVERY BROWSER IN USE TODAY is unable to
securely render HTML. Keeping in mind that not only web browsing,
but also integrated e-mail is at risk, it is a grim thought.
Grim indeed. It will be interesting to see which browser manages to clean
up its act first.
Meanwhile, an improved version of mangleme,
Mr. Zalewski's testing tool, has been released. This version has been
ported to Python (for some reason) and includes some extra tests; its
authors claim to have found a different set of IE crashes.
(
Log in to post comments)