Earlier quoted context omitted.
Or one of the best. Switch wen browsers to strict processong and you will hardly find working web page.
Which are the faults of the authors. No one expects malformed source code to compile, a video with corrupted headers to play properly or a binary containing invalid instructions not to crash. This decision allowed people to get away with broken web pages instead of forcing them to fix their mistakes.
This JPEG is also a webpage
51–60 of 236 posts
Re: This JPEG is also a webpage
#52> Pretty radical, eh? Send money to: lcamtuf@coredump.cx How to send money to your email address? Not that I would send you some, but I wondered how you want to have that money received?
2. Ask him his Bitcoin address
3. Paypal to this address
:)
Re: This JPEG is also a webpage
#53Re: This JPEG is also a webpage
#54https://developer.mozilla.org/en-US/docs/Web/HTML/Element/xm...
It's similar to the pre tag but doesn't require the escaping. I guess you just have to make sure you don't have a closing xmp tag :)
Re: This JPEG is also a webpage
#55> Pretty radical, eh? Send money to: lcamtuf@coredump.cx How to send money to your email address? Not that I would send you some, but I wondered how you want to have that money received?
now specifically in this case, lcamtuf (at google security) is joking and doesn't want your money.
this hack is actually pretty crazy - an arbitrary HTML / jpeg polyglot file that fooled a browser could be used for js injection, say from a site that allowed jpeg file uploads, and validated mime type.
Re: This JPEG is also a webpage
#56Earlier quoted context omitted.
Or one of the best. Switch wen browsers to strict processong and you will hardly find working web page.
Well of course if correctness is not a requirement then it's not being paid attention to. That doesn't in any way indicate that it was a good decision not to require it in the first place.
It's not as if many of the web's security holes are related to whether a page displays valid HTML markup or not.
Re: This JPEG is also a webpage
#57Re: This JPEG is also a webpage
#58 $ curl -o squirrel.html http://lcamtuf.coredump.cx/squirrel/
$ file squirrel.html
squirrel.html: JPEG image data, JFIF standard 1.01, comment: "body { visibility: hidden; } .n { visibilit"
Open the file in a browser and read the page. Then: $ mv squirrel.html squirrel.jpg
Open the renamed file in a browser and only the image appears.I'm not sure what the security implications are. I'm not creative or devious enough to think of anything offhand, but a lot of attack vectors start off with this sort of misdirection.
Re: This JPEG is also a webpage
#59A testament to one of the worst decisions in computing history - not to fail displaying a web page with an error message in case it is not a valid HTML document.
Compare that to JavaScript, which will happily fail if you use new syntax or a missing function, and thus web pages which rely on JS often show up as just a full screen of white when something goes wrong, which it frequently does. That's not to say JS should be as flexible as HTML is here, but it provides an interesting contrast.
Re: This JPEG is also a webpage
#60 _____________________________________________________________________
| |
| =================================================================== |
| |%/^\\%&%&%&%&%&%&%&%&{ Federal Reserve Note }%&%&%&%&%&%&%&%&//^\%| |
| |/inn\)===============------------------------===============(/inn\| |
| |\|UU/ { UNITED STATES OF AMERICA } \|UU/| |
| |&\-/ ~~~~~~~~ ~~~~~~~~~~=====~~~~~~~~~~~ P8188928246 \-/&| |
| |%//) ~~~_~~~~~ // ___ \\ (\\%| |
| |&(/ 13 /_\ // /_ _\ \\ ~~~~~~~~ 13 \)&| |
| |%\\ // \\ :| |/ ~ \| |: 3.21 /| /\ /\ //%| |
| |&\\\ ((iR$)> }:P ebp || |"- -"| || || |||| |||| ///&| |
| |%\\)) \\_// sge || (|e,e|? || || |||| |||| ((//%| |
| |&))/ \_/ :| `._^_,' |: || |||| |||| \((&| |
| |%//) \\ \\=// // || |||| |||| (\\%| |
| |&// R265402524K \\U/_/ // series || \/ \/ \\&| |
| |%/> 13 _\\___//_ 1932 13
source: http://chris.com/ascii/index.php?art=objects/money