    > > Browser bugs [DoS] ... where will you draw a line?
    > DoS bugs that cause permanent damage are treated differently, of course.
    > For example, I could imagine a bug that would corrupt some critical file

    what about Browser bugs[DoS] a XSS vunerable site?
    simple javascript leveraged against a host that has a XSS issue.
    so if you could embed <script>javascript:location.reload()</script>
    in a high traffic, XSS'able site, you could cause a denial of service
    to the webserver from the users trying to view the site.


    will continuily refresh to http://host/stupidscript , since it is XSS'able, the
    returns the script only to be executed again and again and ( you get the
    picture )
    could be used legitematly for a "net-sit-in" to deny a site as well.

    see: http://nothackers.org/pipermail/0day/2003-October/000236.html

    and exactly why does this produce such an odd result?

