[ / / / / / / / / / / / / / ] [ dir / donkey / had / kind / leftpol / rule34 / strek / sw / thestorm ][Options][ watchlist ]

/tech/ - Technology

You can now write text to your AI-generated image at https://aiproto.com It is currently free to use for Proto members.
Name
Email
Subject
Comment *
File
Select/drop/paste files here
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Expand all images

[–]

 No.853730>>853731 >>853733 >>853748 >>853785 [Watch Thread][Show All Posts]

Visiting this link https://iabem97.github.io/chaiOS/ causes Firefox 57.0.4 to freeze (in other words, it's a DoS vulnerability; apparently Rust is not saving it)

Perhaps other browsers may have a trouble too.

Originally it was presented as a proof of concept which crashes some macOS/iOS applications, including safari.

From what I can see, the page content abuses some Unicode characters known as ZALGO text.

I can't report it officially since I was banned on mozilla bugzilla, so can someone repost it to mozilla's bugzilla so they fix their remains of a browser?

and what other mitigations are possible right now?

 No.853731

>>853730 (OP)

and yeah, it works without javascript and even without CSS, that's why it's nastier than your average browser exploit


 No.853733

>>853730 (OP)

also, the html content is weighing 12253982 bytes, and when compressed with xz with default options it's 9444 bytes.

so even just the size of it may be a problem.


 No.853735

for convenience, the compressed downloaded content is here https://my.mixtape.moe/khrssy.xz

(and if it's simply viewed as a text, all text editors I tried have no problem displaying it)


 No.853739

Oh noes, the botnet evolved again. Fucking plebs stop using unicode REEEEEEEEEEEEEEEEEEEEEEEEEEEEE


 No.853740>>853743

my browser just auto closes the tab right when it starts to fuck up then everything is fine


 No.853743

>>853740

which browser is it?


 No.853744

Works fine for me in Lynx. Modern web browsers are just shit.

←←←→→→ (p1 of 2295)

→!-- hello, this was written by Abraham Masri @cheesecakeufo -->

<!-- I discovered this bug in like 10 minutes -->

<head>

<meta property="og:title" content="

+

+t

+93xwz=‍ ‍'9eEJE'd5

+t

+

+

+t

+

+t


 No.853748

>>853730 (OP)

Pale Moon works fine.


 No.853752

I opened the page with Links and it has ~11MB. No way I'm going to let my browser load that.


 No.853785>>853810

>>853730 (OP)

It displayed "Page is loading..." and made Firefox (58.0b15) very sluggish. I had no problem closing the tab though.

>apparently Rust is not saving it

You know that Firefox has not been completely rewritten in Rust, right?


 No.853789

Didn't freeze, but slowed down to a crawl and ate cpu like a bitch on ff 52.


 No.853795

Says "Page is loading" and doesn't download anything on qutebrowser


 No.853810

>>853785

>You know that Firefox has not been completely rewritten in Rust, right?

Of course, that's a joke.

>very sluggish

perhaps I was too impatient to wait. UI was completely unresponsive for about 10 seconds.




[Return][Go to top][Catalog][Screencap][Nerve Center][Cancer][Update] ( Scroll to new posts) ( Auto) 5
13 replies | 0 images | Page ?
[Post a Reply]
[ / / / / / / / / / / / / / ] [ dir / donkey / had / kind / leftpol / rule34 / strek / sw / thestorm ][ watchlist ]