[Full-Disclosure] Browser bugs [DoS] - Do they bite?
From: morning_wood (se_cur_ity_at_hotmail.com)
Date: 04/11/04
- Previous message: Perrymon, Josh L.: "RE: [Full-Disclosure] Cisco LEAP exploit tool..."
- In reply to: Heikki Toivonen: "Re: [Full-Disclosure] Browser bugs [DoS] ... where will you draw a line?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: <full-disclosure@lists.netsys.com> Date: Sun, 11 Apr 2004 01:32:34 -0700
> > Browser bugs [DoS] ... where will you draw a line?
>
> DoS bugs that cause permanent damage are treated differently, of course.
> For example, I could imagine a bug that would corrupt some critical file
what about Browser bugs[DoS] a XSS vunerable site?
simple javascript leveraged against a host that has a XSS issue.
so if you could embed <script>javascript:location.reload()</script>
in a high traffic, XSS'able site, you could cause a denial of service
to the webserver from the users trying to view the site.