Opened 3 years ago

Closed 13 months ago

#20496 closed defect (worksforme)

Website causes tor to become unresponsive.

Reported by: Dbryrtfbcbhgf Owned by: tbb-team
Priority: High Milestone:
Component: Applications/Tor Browser Version:
Severity: Major Keywords: tbb-crash
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

If you go to http://bad.neon2.ml/ on tor, the browser will become unresponsive. I attached the website sorce code to this bug report. This user on twitter claims to of created this exploit. https://twitter.com/ceaec

Child Tickets

Attachments (1)

Bug.zip (115.3 KB) - added by Dbryrtfbcbhgf 3 years ago.

Download all attachments as: .zip

Change History (9)

Changed 3 years ago by Dbryrtfbcbhgf

Attachment: Bug.zip added

comment:1 Changed 3 years ago by Dbryrtfbcbhgf

The attachment contains the source code of the website that causes the exploit.

comment:2 Changed 3 years ago by Dbryrtfbcbhgf

Severity: NormalCritical

comment:3 Changed 3 years ago by cypherpunks

Component: - Select a componentApplications/Tor Browser
Owner: set to tbb-team

comment:4 Changed 3 years ago by bugzilla

Keywords: tbb-crash added
Status: newassigned

After doing duty cycles during being unresponsive (w/o detecting unresponsive scripts) and showing something like "RIP TOR luv u" at the end, TBB has exited itself with all opened tabs. Nice.
(TBB latest stable :) on Medium-High)
(Why did that guy disclose such wonderful old features of FF?)

comment:5 Changed 3 years ago by gk

Priority: ImmediateHigh
Severity: CriticalMajor

comment:6 Changed 13 months ago by traumschule

Resolution: fixed
Status: assignedclosed

Not reproducible with 8.0.2.

Downloaded und extracted Bug.zip and opened the html files, no crash:

JavaScript error: resource://gre/modules/WebRequestContent.js, line 118: TypeError: window is undefined
JavaScript error: file:///path/to/Downloads/20496/bad.neon2.ml.html, line 1: ReferenceError: slowAES is not defined

comment:7 Changed 13 months ago by traumschule

Resolution: fixed
Status: closedreopened

Correct resolution

comment:8 Changed 13 months ago by traumschule

Resolution: worksforme
Status: reopenedclosed
Note: See TracTickets for help on using tickets.