HTML5 vulnerabilities can cause hard disks to be filled with junk data

Source: Internet
Author: User
Netease technology news March 4 news, according to foreign media reports, a recent developer found that HTML5 encoding language vulnerabilities will make the website Generate several GB of junk data, in a short time full of hard disks, this issue affects multiple popular browsers. Netease technology news March 4 news, according to foreign media reports, recent developers found that HTML
5. A vulnerability in the encoding language can cause the website to generate several GB of junk data and fill the hard disk in a short period of time. Multiple popular browsers are affected by this vulnerability.

Feross
Abukhadijeh) said that the data dumping problem occurs in most Web browsers, including Apple Safari, Google Chrome, Microsoft IE and Opera. Mozilla Firefox is the only browser that can block data dumping, the Storage Limit of Firefox is 5 MB.


The root cause of this problem is HTML
5. The method for processing local data storage is related. Although the storage parameter settings of Each browser are different, most of them support user-defined upper limit, which makes the storage space on the user's computer at least 2.5 MB.


The vulnerabilities discovered by abhatdij can generate numerous temporary websites connected to websites accessed by users, thus bypassing the Data Storage Limit. Because most browsers do not consider unexpected situations, affiliated websites can store locally, and the storage limit is the same as that of the primary site. By generating a large number of connected websites, this vulnerability can dump a large amount of data on the affected computers.


Abhatdijie used the solid state drive's MacBook to test the vulnerability.
The Pro can dump 1 GB of data every 16 seconds. He pointed out that a 32-bit browser like Chrome may crash before the hard disk is full.


Abhatdijie has released code to exploit this vulnerability, and has created a website named Filldisk to attract people's attention to this issue. The vulnerability report has been sent to affected browser vendors. abhatdijie said that no malicious use of its code has been found. (Le bang)

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.