edit: to clarify, i'm talking about in the page itself rather than the favicon.
edit: to clarify, i'm talking about in the page itself rather than the favicon.
Typically an ad-blocker or script blocker can be used to prevent the image from downloading. But I don't know of a blocker add-on that worries about favicon.
Overall while annoying and a bit strange that this wasn't anticipated and fixed long ago I'd say this is probably a non-issue. As another poster said I don't see a payoff here so I doubt it will be actively exploited in some "internet screeching to a halt" kind of way.
> Overall while annoying and a bit strange that this wasn't anticipated and fixed long ago I'd say this is probably a non-issue. As another poster said I don't see a payoff here so I doubt it will be actively exploited in some "internet screeching to a halt" kind of way.
favicons can also be inserted dynamically.
http://stackoverflow.com/questions/260857/changing-website-f...If some site has a js injection bug, or there is someone doing MiTM like the Great Firewall, I suppose they could inject a favicon link that referenced some location on another site, with the intent towards DoS.
It also occurs to me that given the ability to insert yourself between the client and the server has to open up a number of possible attack vectors that are more worth while than crashing the client. I get (I think) the point about if censorship is the goal this is a way to make clients stay away from a particular server but if you're in a position to MITM them why not just return 404's and be done with it?
Not trying to argue, :-) Just want to make sure I'm understanding your point correctly...
If you can inject html though, a hidden image would probably would just as well. Although the behavior of chrome apparently still requesting the favicon file after the tab has closed, and possibly storing it in the history or bookmark file, may make this more or less appealing. Unsure.
http://www.netresec.com/?page=Blog&month=2015-03&post=China%...
also, interesting discussion from wayback: