Re: XML scripting in IE, Outlook Express

2001-04-30 Thread Ben Ford
[EMAIL PROTECTED] wrote: > >Further, we can crash everything that touches this extremely hard. Both >IE5.5. and OE.5.5. Stripping the already bare minimum demos, in IE5.5. we >achieve: > Yes, it also seems to have done more than that. Since I looked at the demo this morning my win2k box hasn'

Re: SurfControl Bypass Vulnerability

2001-03-26 Thread Ben Ford
The idea of IP based penetration is also flawed, in that you'd get the default domain of the box anyways. Unless that default domain has an index page to give you a choice of virtual hosts (and many/most don't), you wouldn't be able to access the desired http://www.juicysex.com anyways. -b Dan