Yet Another Internet Explorer Crash

Yet another Internet Explorer crash has been discovered! This one is incredibly simple to reproduce, but doesn’t look (easily) exploitable because it’s a null pointer write.
To reproduce, simply load a page containing

<html>
<form>
<input type crash>
</form>
</html>

That’s it! I’ve set one up here. Don’t click it if you are using Internet Explorer!

It also affects Outlook, Frontpage, and a few others.

See the BugTraq Listing for details.

The Lord Of The Rings: The Return Of The King

I just saw The Lord Of The Rings: The Return of The King this afternoon. It was absolutely fantastic.

It’s the longest film of the trilogy, running to a bum-numbing 3 hours 20 minutes! But I have to say it was well worth it. I cannot recommend it enough.

The final part of the story is told extremely well. The scenes at Minas Tirith are breath taking. The scale of the sets is awesome! The battle scenes are great, but especially the beasts and the war machines had me perched on the edge of my seat.

I found the dialogue much more interesting in this final part. Although, in a cinema packed with school age children who are unable to concentrate without talking for more than about 20 minutes, it was, alas, not possible to actually hear all the dialogue. I was surprised that so many children were watching, but pleased too, despite the noise levels, that most of them were able to sit for that length of time.

I think Peter Jackson has done a marvelous job of surreptitiously bringing back long films to the cinema. He has proven that you can make a very long film, that you can get an audience to sit still for more than two and a half hours. All you need is a good story told well. You don’t need mega stars, you don’t need naked bodies or exploding cars, just good characters well developed, and good storylines. Action? Yeah sure! But no blood and spilling guts required. Special Effects? Absolutely! But not for their own sake.

One consequence of all the hushed (and not so hushed sometime) conversations going on around me was that I could get an insight into the people’s reactions to the movie. It was refreshing to hear that they ‘got it’, that they followed the plot and the interplay between the characters. Though some may not have had all the details quite right (“Is he back in the Spire?” “It’s the ‘Shire’ dummy!”).

The only low spot I can remember from the whole movie was that some of the acting between Frodo and Sam was a little less than convincing. I don’t think they quite got the relationship across properly. The three or four girls in the row behind me were less than gripped by the big emotional scenes and amused themselves by imagining (aloud, unfortunately) the conversation with a gay slant.

I will have to see it again, probably in a late showing, to give myself a chance of hearing all of the last twenty minutes. Most of which was impossible to hear today after the attention span of some of the audience was exceeded.

Recommended.

Blogshares Coming back!

Wow, it looks like blogshares will be coming back after all.

A solid agreement has been reached between BlogShares founder Seyed Razavi and technologist Jay Campbell — the site is coming back!
Premium memberships will be extended one month to make up for this downtime. If you had 8 months left, now you have 9.
The reconstituted BlogShares team is doing cartwheels over the possibilities that 2004 brings.
Check back for more notices, and soon a working site.

Another IE security Issue

Yet another Internet Explorer exploit has been discovered. This one is ripe for many of the phishing scams that have been going around.

Secunia have a good, detailed advisory.

The vulnerability is caused due to an input validation error, which can be exploited by including the “%01” URL encoded representation after the username and right before the “@” character in an URL.
Successful exploitation allows a malicious person to display an arbitrary FQDN (Fully Qualified Domain Name) in the address bar, which is different from the actual location of the page.

Steve Minutillo has an example. Andy at absoblogginlutely has another example.

Remember, these only ‘work’ as intended in Internet Explorer.

Olive Berkon

Jan’s mum, Olive, passed on six years ago today. We still miss her.

When I must leave you
For a little while
Please do not grieve and shed wild tears
And hug your sorrows to you through the years
But start out bravely with a gallant smile
And for my sake and in my name
Live on and do all things the same
Feed not your loneliness on empty days
But fill each waking hour in useful ways
Reach out your hand in comfort and in cheer
And I in turn will comfort you and hold you near
And never, never be afraid to die
For I am waiting for you
In the sky
— Helen Steiner Rice

Good Luck Jamie

My daughter Jamie has her opening night of her first pantomime tonight. The stage school she attends has a pantomime every year. This year Jamie will be performing about 6 songs as part of the chorus in the show and she has several dances too. I will be going to see her tomorrow. I’m really looking forward to it. If her singing around the house is an indication she will be great!

Good luck Jamie.
Lots of Love,

Mum and Dad
XOXOXOXOX

BlogShares – Closed Down

It looks like Seyed has finally thrown in the towel. BlogShares has officially closed down.

I am sorry to announce that BlogShares will not be reopening after the current technical difficulties are resolved. Currently, the database server is dead and looks to be for the next few days.

It was fun while it lasted. But as Seyed himself says there has been a decline of quality service, new features and ultimately income for the site in the last couple of months.

I’m glad to have been part of it from quite early on (I was member number 341, joined at the end of March).