Suppress malicious invocation via img HTML tag
- aeon
- Posts: 163
- Joined: December 7th, 2002, 8:00 am
Suppress malicious invocation via img HTML tag
Sometimes I come across those pages with malicious
img tags on them to crash a browser, for example
<img src=mailto:111111> opens up thousands of mailer windows and
<img src=telnet://...
<img src=pnm://...
<img src=news://...
<img src=file://...
are annoying too, if thousands of them are written in one page you load up. How about implementing some restriction on the number
such invocation can occur when they are not one of general protocols that is http? It's nice you can set it in preferences.
You may suggest using local proxies to filter those bad codes, but I'm too lazy to do it so please don't mention about such tools.
img tags on them to crash a browser, for example
<img src=mailto:111111> opens up thousands of mailer windows and
<img src=telnet://...
<img src=pnm://...
<img src=news://...
<img src=file://...
are annoying too, if thousands of them are written in one page you load up. How about implementing some restriction on the number
such invocation can occur when they are not one of general protocols that is http? It's nice you can set it in preferences.
You may suggest using local proxies to filter those bad codes, but I'm too lazy to do it so please don't mention about such tools.
- alanjstr
- Moderator
- Posts: 9100
- Joined: November 5th, 2002, 4:43 pm
- Location: Anywhere but here
- Contact:
I wonder if there is a Bugzilla bug for that. It sounds like a Mozilla problem.
I have yet to run into any page that is formed like that. Do you have an example?
I have yet to run into any page that is formed like that. Do you have an example?
Former UMO Admin, Former MozillaZine General Mod
I am rarely on mozillaZine, so please do not send me a private message.
My Old Firefox config files
I am rarely on mozillaZine, so please do not send me a private message.
My Old Firefox config files
- aeon
- Posts: 163
- Joined: December 7th, 2002, 8:00 am
alanjstr wrote:I wonder if there is a Bugzilla bug for that. It sounds like a Mozilla problem.
I have yet to run into any page that is formed like that. Do you have an example?
Yes, mozilla scope may be appropriate, but I know
when it is submit to Moz it'll take longer to be implemented in it (sigh)
As for an example,
view-source:http://www.google.com/search?q=cache:QHquADR7vuUC:www.strangeworld.org/
if you have courage load it up without view-source.
It contains JavaScript loop crash in additon to <img src=mailto:...>, but JS thing is not relevant here, look at the bottom of the source.
If you run Phoenix on MS Windows, it'll open up Outlook Express.
I don't know Linux well, but on MS Windows telnet:// can invoke hyperterminal and pnm:// can invoke RealPlayer.
- alanjstr
- Moderator
- Posts: 9100
- Joined: November 5th, 2002, 4:43 pm
- Location: Anywhere but here
- Contact:
Ok, this is a serious bug that will cause a DoS to the user. My Lotus Notes went bonkers and I had to physically pull the plug on my machine to get it to stop.
I'm gonna contact Mozilla security for advice and will post back here.
I'm gonna contact Mozilla security for advice and will post back here.
Former UMO Admin, Former MozillaZine General Mod
I am rarely on mozillaZine, so please do not send me a private message.
My Old Firefox config files
I am rarely on mozillaZine, so please do not send me a private message.
My Old Firefox config files
- gorn
- Posts: 59
- Joined: January 1st, 2003, 1:17 am
- Location: 127.0.0.1
- Contact:
- daihard
- Folder@Home
- Posts: 16633
- Joined: November 17th, 2002, 6:27 pm
- Location: Lynnwood, WA
- Contact:
gorn wrote:no problem here
linux
I know. Assuming it's not going to kill my RH box, I tried that site. I was right -- since the mailer association doesn't exist, no mail application got opened. (Tells you that a Linux-specific bug can be helpful!)
Kubuntu 8.04 (kernel 2.6.24-25-generic) / KDE 3.5.10
CentOS 4.8 (kernel 2.6.9-78.0.22.ELsmp) / KDE 3.5.10
Mac OS X 10.6.1 (Snow Leopard) / iPhone 3GS (32GB black)
CentOS 4.8 (kernel 2.6.9-78.0.22.ELsmp) / KDE 3.5.10
Mac OS X 10.6.1 (Snow Leopard) / iPhone 3GS (32GB black)
- SHINE
- Posts: 19
- Joined: January 3rd, 2003, 7:15 am
- Location: http://www.mbforums.org/
- Contact:
Thank god win xp is stable as hell, I don't want to open that link on a win 95/98 machine.
admin @ www.mbforums.org
- alanjstr
- Moderator
- Posts: 9100
- Joined: November 5th, 2002, 4:43 pm
- Location: Anywhere but here
- Contact:
Win2k is very stable. I just wasn't patient enough to let that page finish loading.
Former UMO Admin, Former MozillaZine General Mod
I am rarely on mozillaZine, so please do not send me a private message.
My Old Firefox config files
I am rarely on mozillaZine, so please do not send me a private message.
My Old Firefox config files
- daihard
- Folder@Home
- Posts: 16633
- Joined: November 17th, 2002, 6:27 pm
- Location: Lynnwood, WA
- Contact:
alanjstr wrote:Win2k is very stable. I just wasn't patient enough to let that page finish loading.
I am not going to start another Windows-vs-Linux flame war here.
Kubuntu 8.04 (kernel 2.6.24-25-generic) / KDE 3.5.10
CentOS 4.8 (kernel 2.6.9-78.0.22.ELsmp) / KDE 3.5.10
Mac OS X 10.6.1 (Snow Leopard) / iPhone 3GS (32GB black)
CentOS 4.8 (kernel 2.6.9-78.0.22.ELsmp) / KDE 3.5.10
Mac OS X 10.6.1 (Snow Leopard) / iPhone 3GS (32GB black)
- alanjstr
- Moderator
- Posts: 9100
- Joined: November 5th, 2002, 4:43 pm
- Location: Anywhere but here
- Contact:
Just because I use Win2k doesn't mean I think it's superior to Linux. No response from mozilla.org yet.
Former UMO Admin, Former MozillaZine General Mod
I am rarely on mozillaZine, so please do not send me a private message.
My Old Firefox config files
I am rarely on mozillaZine, so please do not send me a private message.
My Old Firefox config files
- aeon
- Posts: 163
- Joined: December 7th, 2002, 8:00 am
Well I myself uses WinXP and OS is stable, though
sudden resource takeover may cause pageout or something to lower overall system performance.
The probelm is, the quickest way to stop this spawning
many many windows is to kill the Phoenix process from task manager and you'll lose the data you
are looking in another tab or another Phoenix window.
BTW those malicious invocation is really old, old
way to crash browser, and I suspect there's some
reason that Moz people don't implement any
restriction, for example, they are too lazy to
implement such thing since you can use 3rd
party local proxies, or they may suggest
GNU/Linux or *BSD:P
But I hope Phoenix goes more far on this matter.
sudden resource takeover may cause pageout or something to lower overall system performance.
The probelm is, the quickest way to stop this spawning
many many windows is to kill the Phoenix process from task manager and you'll lose the data you
are looking in another tab or another Phoenix window.
BTW those malicious invocation is really old, old
way to crash browser, and I suspect there's some
reason that Moz people don't implement any
restriction, for example, they are too lazy to
implement such thing since you can use 3rd
party local proxies, or they may suggest
GNU/Linux or *BSD:P
But I hope Phoenix goes more far on this matter.
- daihard
- Folder@Home
- Posts: 16633
- Joined: November 17th, 2002, 6:27 pm
- Location: Lynnwood, WA
- Contact:
alanjstr wrote:Just because I use Win2k doesn't mean I think it's superior to Linux. No response from mozilla.org yet.
I know. I actually agree that 2000 is a bit more stable than XP, especially when XP is used with Luna.
Kubuntu 8.04 (kernel 2.6.24-25-generic) / KDE 3.5.10
CentOS 4.8 (kernel 2.6.9-78.0.22.ELsmp) / KDE 3.5.10
Mac OS X 10.6.1 (Snow Leopard) / iPhone 3GS (32GB black)
CentOS 4.8 (kernel 2.6.9-78.0.22.ELsmp) / KDE 3.5.10
Mac OS X 10.6.1 (Snow Leopard) / iPhone 3GS (32GB black)
- alanjstr
- Moderator
- Posts: 9100
- Joined: November 5th, 2002, 4:43 pm
- Location: Anywhere but here
- Contact:
The odd thing was that I couldn't even get task manager to kill the phoenix process.
Former UMO Admin, Former MozillaZine General Mod
I am rarely on mozillaZine, so please do not send me a private message.
My Old Firefox config files
I am rarely on mozillaZine, so please do not send me a private message.
My Old Firefox config files
- djst
- Moderator
- Posts: 2826
- Joined: November 5th, 2002, 1:34 am
- Location: Sweden
- Contact:
daihard wrote:alanjstr wrote:Just because I use Win2k doesn't mean I think it's superior to Linux. No response from mozilla.org yet.
I know. I actually agree that 2000 is a bit more stable than XP, especially when XP is used with Luna.
Do you actually notice a difference in stability when using the luna appearance? I never have.
- David James
- Posts: 1321
- Joined: November 4th, 2002, 10:19 pm
- Location: Ottawa, Ontario, Canada
- Contact: