Author Topic: Firefox + history.dat DoS  (Read 1762 times)

0 Members and 1 Guest are viewing this topic.

Offline Newby

  • x86
  • Hero Member
  • *****
  • Posts: 10877
  • Thrash!
    • View Profile
Firefox + history.dat DoS
« on: December 21, 2005, 01:51:08 pm »
http://tech-security.com/blog/files/PoC.html

Don't click it unless you plan on deleting history.dat or using vim (like I) to type '99999999999dd' or so.

Not sure if it was posted here, but since it affects both Windows and Linux Firefox's I figured I'd put it here!

(Latest Firefox, btw.)

It crashes because it's parsing, and it's huge. :P
- Newby
http://www.x86labs.org

Quote
[17:32:45] * xar sets mode: -oooooooooo algorithm ban chris cipher newby stdio TehUser tnarongi|away vursed warz
[17:32:54] * xar sets mode: +o newby
[17:32:58] <xar> new rule
[17:33:02] <xar> me and newby rule all

I'd bet that you're currently bloated like a water ballon on a hot summer's day.

That analogy doesn't even make sense.  Why would a water balloon be especially bloated on a hot summer's day? For your sake, I hope there wasn't too much logic testing on your LSAT. 

Offline iago

  • Leader
  • Administrator
  • Hero Member
  • *****
  • Posts: 17914
  • Fnord.
    • View Profile
    • SkullSecurity
Re: Firefox + history.dat DoS
« Reply #1 on: December 21, 2005, 02:00:04 pm »
I tried that when it was first posted, it was pretty disappointing. 

Unless it got better?

Offline Blaze

  • x86
  • Hero Member
  • *****
  • Posts: 7136
  • Canadian
    • View Profile
    • Maide
Re: Firefox + history.dat DoS
« Reply #2 on: December 21, 2005, 06:38:21 pm »
Title changed to AAAAAAAAAAA, History... fine.
And like a fool I believed myself, and thought I was somebody else...