OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Full-disclosure] Possible DoS in TamperData Add-on v10.1.0 for FireFox 3.0.8

Valdis.Kletnieksvt.edu
Date: Sun May 03 2009 - 15:44:28 CDT


On Fri, 01 May 2009 23:59:35 +1000, Xia Shing Zee said:

> The loop tries to constantly read the streaming HTTP data. Firefox will
> become unresponsive and will offer the user to stop the script.
> The script can be continued, but with files over 8.00mb there is a
> possible DoS, as the script must constantly be 'continued'.

http://tamperdata.mozdev.org/warnings.html says:

# Request/Response pairs are stored in javascript arrays. Run this extension
for a long time any firefox may run out of memory - don't do this

Sounds like it's probably a known issue - you run long enough, those javascript
arrays are gonna get big and piggy, and trigger the "stop the script" warning.
Or can you verify that you're seeing some different issue?

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFJ/gIscC3lWbTT17ARAqdfAJ9MV701jiYXUDxwDNmoL+TROjITPwCfU8Rs
2BUl0VpBRlvILRGz7hAA/Kk=
=OA0K
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/