Issue metadata
Sign in to add a comment
|
A single click can crash whole remote user system using chrome browser
Reported by
develope...@gmail.com,
Jan 12
|
||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3642.0 Safari/537.36 Steps to reproduce the problem: I've created a test page for jquery - click on the link - https://domstorm.skepticfx.com/modules/run?id=5739c438c9e0250300990935 What is the expected behavior? The browser is not able to control the request made by js files which running on web pages and it causes to crash whole user system. It should be able to control request frequencies. What went wrong? I've created a sandbox environment in a single web page to fuzz the jquery dialog box during the test I found the system is crashed before making less than 50 requests in a total of 1700 requests which is performing self ddos. A malicious user can crash remote user whole system by only send a malicious link after starting the process then the user can't stop it because it crashes browser with Operating system. Did this work before? N/A Chrome version: 73.0.3642.0 Channel: stable OS Version: Parrotsec os 4.4 Flash Version: 32.0.0.114 This attack may cause loss of the users current time processes which are running in the background which can lead the important data loss. I've tried it 3 times and my os was crashed and to get rid of I needed whole system shutdown via power switch.
,
Jan 15
The page had no problem at all on Debian Rodete. This might be a local OS issue. Reporter, can you test on other OS?
,
Jan 16
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by phanindra.mandapaka@chromium.org
, Jan 13