[tor-bugs] #9901 [TorBrowserButton]: DoS of TBB when no Content-Type header and more than 512 bytes of content are sent

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Jan 30 11:16:12 UTC 2014


#9901: DoS of TBB when no Content-Type header and more than 512 bytes of content
are sent
-------------------------+-------------------------------------------------
     Reporter:  sqrt2    |      Owner:  mikeperry
         Type:  defect   |     Status:  reopened
     Priority:  normal   |  Milestone:
    Component:           |    Version:
  TorBrowserButton       |   Keywords:  tbb-usability, interview, tbb-crash
   Resolution:           |  Parent ID:
Actual Points:           |
       Points:           |
-------------------------+-------------------------------------------------

Comment (by gk):

 As a work-in-progress report: I spent one day on trying to get the hooking
 approach to work but failed. While the hooking is working and I can filter
 the messages properly I encountered websites that are getting my browser
 crashed reliably with that setup. This happens even if I don't do anything
 besides hooking the component. So, we need something different here.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9901#comment:83>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list