AwSnap – This link crashes Chrome
github.com
github.com
Can I ask why you took the approach of making a Github repo to post this rather than filing a Chromium bug?
I talked about the lack of reply to the comment where this was pointed out.
Just asking why he didn't it and then leaving the conversation possibly means he either didn't wait for the answer or was bothered with it?
I don't have security-bugs access, but I explained offline to the OP that "Won't Fix" covers a lot of cases, including "already fixed" / "duplicate", not simply "your bug report is being ignored".
OP also sent me some more information about the BrowserStack setup, and it looks like both the M42 and M43 builds that OP was testing against are nearly a month old and before the fix (merged to M42 late in beta phase, M43's still in dev/canary stage).
And you are right, it was initially marked as "Won't Fix" because it was not immediately reproducible, but further research yielded it being discovered as an "already fixed" dupe.
FYI it seems there is a minimum age (a minute or so) to a comment in order to reply. At least that was my experience last night.
Aha, the automatic flamewar limiter I guess. Happens to me as well. (clicking on the xx minutes ago link seems to help most of the time.)
> I don't have security-bugs access, but I explained offline to the OP that "Won't Fix" covers a lot of cases, including "already fixed" / "duplicate", not simply "your bug report is being ignored".
I don't know what I'd do if anyone reporting to me used wontfix for all those kind of cases. It doesn't exactly encourage bug reporting.
The library I was using converted the port text into a 32 bit integer but the library didn't account for the possibility that someone supplied a port well over the 32 bit int limits. I was curious how many tools that use URLs would suffer similar fates and whether there might be any interesting security vulnerabilities.
Just goes to show, no matter how much crazy you've seen, there's likely crazier things hidden from you across the Internet ;)
[1]: http://commoncrawl.org/ [2]: https://twitter.com/Smerity/status/576339945041707008
[1] http://stackoverflow.com/questions/417142/what-is-the-maximu...
Edit - followed links
Have added new crash options for users with NoScript (even if you're blocking 302s - try right clicking).
But the reason I posted this is because it doesn't rely on Javascript to eat up memory- anyone can post a malformed/long link to a web forum and crash the thread/site for other Chrome users immediately, without clicking thru.
➜ ~ curl http://crashfirefox.com/
....................../´¯/)
....................,/¯../
.................../..../
............./´¯/'...'/´¯¯`·¸
........../'/.../..../......./¨¯\
........('(...´...´.... ¯~/'....')
.........\.................'...../
..........''...\.......... _.·´
............\..............(
..............\.............\...
SNITCHES GET STITCHES
....................../´¯/)
....................,/¯../
.................../..../
............./´¯/'...'/´¯¯`·¸
........../'/.../..../......./¨¯\
........('(...´...´.... ¯~/'....')
.........\.................'...../
..........''...\.......... _.·´
............\..............(
..............\.............\...
SNITCHES GET STITCHES
....................../´¯/)
....................,/¯../
.................../..../
............./´¯/'...'/´¯¯`·¸
........../'/.../..../......./¨¯\
........('(...´...´.... ¯~/'....')
.........\.................'...../
..........''...\.......... _.·´
............\..............(
..............\.............\...
SNITCHES GET STITCHES
➜ ~ curl http://crashfirefox.com | wc -l
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 3613k 0 3613k 0 0 2020k 0 --:--:-- 0:00:01 --:--:-- 2019k
120000 curl -i -H 'User-Agent: Firefox' crashfirefox.com | head -n 80 | cut -b 1-100I was initially turned off from Chrome in its early versions because it seemed that tabs crashed much more easily, since it wasn't as big a deal to have a tab crash. Firefox crashes as a whole, so it has much more motivation to diligently make sure its subsystems are not prone to crashing on high-level documents / languages, however malformed they may be.
But as was posted below, it's still quite easy to lock up Firefox. So I applaud crashfirefox.com as well as this Chrome demonstration, they're needed to keep the balance between robustness and new features.
1) Most people don't have SSL enabled for most (if any) sites that are optional.
2) Most normal users are using the standard build for MacOS/Win, not the dev channel, and not Linux.
3) This requires no XSS or anything remotely tricky. Just a couple hundred bytes of HTML, and that's it.
4) Most web forum filters and formatting code (including Markdown) let this thru just fine.
Maybe I'm blowing it out of proportion, but if you wanted to be a jerk to a whole lot of people very easily, you probably could.
EDIT: Grammar
But a HK clone was crashed.
https://code.google.com/p/chromium/issues/detail?id=472899
and fixed in:
https://chromium.googlesource.com/chromium/src/+/5922e15ca3d...
FWIW
Its because HN defaults to https. Https rendering of a site seems to be unaffected by this bug.