6 ms·
> ...But ofcource if you went to web sites with malicious HTML you could get ownzored because of bugs in the rendering engine. It's funny, when the Windows sou
by Hrundi 13y ago
> ...But ofcource if you went to web sites with malicious HTML you could get ownzored because of bugs in the rendering engine.
It's funny, when the Windows source code was leaked (opened?) in 2004[1], folks soon discovered a vulnerability in the BMP renderer[2].
[1] http://slashdot.org/story/04/02/12/2114228/windows-2000-windows-nt-4-source-code-leaks http://slashdot.org/story/04/02/12/2114228/windows-2000-wind...
[2] http://www.securitytracker.com/id/1009067 http://www.securitytracker.com/id/1009067
- ksk 13y agoI doubt it had anything to do with the source leak. Most security bugs these days are found via automated means - fuzzing, fault injection, etc. But OTOH these bugs become useful in other ways. I believe there was an ios jailbreak method where you simply visit a website on your iphone (jailbreak.me? .com?) and your device is rooted/jailbroken due to a bug in Safari's PDF renderer.