From owner-freebsd-security Mon May 17 7:33:41 1999 Delivered-To: freebsd-security@freebsd.org Received: from roble.com (roble.com [199.108.85.50]) by hub.freebsd.org (Postfix) with ESMTP id 767B314F4C for ; Mon, 17 May 1999 07:33:35 -0700 (PDT) (envelope-from sendmail@roble.com) Received: from roble2.roble.com (roble2.roble.com [199.108.85.52]) by roble.com (Roble1b) with SMTP id HAA14552 for ; Mon, 17 May 1999 07:33:36 -0700 (PDT) Date: Mon, 17 May 1999 07:33:33 -0700 (PDT) From: Roger Marquis X-Sender: Roger Marquis Reply-To: Roger Marquis To: security@FreeBSD.ORG Subject: HTML DOS? (http://microsoft.com/NTServer/all/Downloads.asp) In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org Has anyone attempted to browse: http://microsoft.com/NTServer/all/Downloads.asp using Netscape Navigator and noticed what seems to be an HTML denial of service? I've tested this page with Javascript on and off, Java on and off, cookies on and off, stylesheets off, under FreeBSD, Linux and Solaris and the behavior is consistent: * Navigator freezes for several seconds * CPU utilization climbs briefly to near 100% * memory usage climbs by 11MB * the 11MB or memory are not released even after leaving the page and clearing disk and RAM caches. The page shows two possible sources for this extremely unusual browser behavior: Using lynx to downloaded the jscripts.js and Netscape.css scripts there is, as expected, a good deal of browser-specific code. Is there a csslint or javascript debugging utility which might identify this Unix-Netscape specific problem? -- Roger Marquis Roble Systems Consulting http://www.roble.com/ To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message