Vulnerability Development mailing list archives

Re: help:// protocol in Windows XP Prof


From: NETKOJI <netkoji () poczta onet pl>
Date: Thu, 08 Jul 2004 00:16:55 +0200


Hello vuln-dev,

Bartosz Kwitkowski wrote:

 There is funny thing in Internet Explorer 6.0 - Windows XP Professional (fully patched).
When you are writing address in IE you can replace http:// by help:// example:
 http://wb.pl/bartosz = help://wb.pl/bartosz
and than hit <ENTER>... Page will open...
 other...
 help://www.securityfocus.com - looks funny, isn't? :-)
 when IE opens page changes help:// to http://
 BUT, BUT,
 when you are create hyperlink <a href="help://wb.pl/bartosz">check</a>
 it won't work - IE says syntax error...
 I'm trying to exploit this...
 Best regards,
 Bartosz Kwitkowski


The same 'bug' applies to all other IE browsers below 6.0 (Win98SE and Win2K). Doesn't look like anything dangerous to me though...

NETKOJI



Current thread: