Bug 19270 - WebKit crashes running IE Bait & Switch attack page
Summary: WebKit crashes running IE Bait & Switch attack page
Status: RESOLVED WORKSFORME
Alias: None
Product: WebKit
Classification: Unclassified
Component: New Bugs (show other bugs)
Version: 528+ (Nightly build)
Hardware: PC Windows XP
: P1 Normal
Assignee: Nobody
URL: http://lcamtuf.coredump.cx/ierace/
Keywords:
Depends on:
Blocks:
 
Reported: 2008-05-27 11:29 PDT by Eric Seidel (no email)
Modified: 2010-03-31 16:38 PDT (History)
3 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Eric Seidel (no email) 2008-05-27 11:29:44 PDT
WebKit crashes running IE Bait & Switch attack page

Mac Safari does not seem vulnerable to the IE Bait and Switch attack.  I don't really suspect that Win Safari is either.  However, closing the attack window (the window which pops up and loads google.pl repeatedly) while the test is running crashes Safari.

I was using Safari 3.1 with heap-checking enabled (gflags.exe).

1.  Open http://lcamtuf.coredump.cx/ierace/
2. Click on "Click here to begin test"
3.  Close the window that appears and is running the test (opening google.pl repeatedly).
4.  Crash!
Comment 1 Alexey Proskuryakov 2010-03-31 16:37:29 PDT
Eric, does this still happen for you? Could you attach a crash log?
Comment 2 Eric Seidel (no email) 2010-03-31 16:38:57 PDT
I haven't used Windows Safari in a very long time.