Re: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)

2007-01-04 Thread Larry Seltzer
-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws) A while ago, apparently angry with Larry Seltzer, I penned a quick write-up on the possible issues with race conditions triggered by asynchronous browser events (such as JavaScript timers) colliding with synchronous content

Re: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)

2007-01-04 Thread Michal Zalewski
On Thu, 4 Jan 2007, Larry Seltzer wrote: I hope you're still not angry! It took months of therapy, but I recovered ;) I just tried your demo on IE7. It took a while longer but does seem to have locked up. Were you looking at IE6 or IE7, and is the behavior any different? I tested several