collapse collapse

* Archive Notice

This is an Archive Forum.

The content in this forum may be out-of-date or have been superseded by newer information, and links in forum pages to other sites may not work. This forum contains archives for future reference.

Visit our thread at Simple Machines Forum for current support.

* User Info

 
 
Welcome, Guest. Please login or register.

* Who's Online

  • Dot Guests: 191
  • Dot Hidden: 0
  • Dot Users: 0

There aren't any users online.

* Shoutbox

Refresh History
  • Shoutbox is not for support!
  • {OCS}MasterSeal: Yup, Still adore SP
    April 21, 2019, 07:08:06 PM
  • {OCS}MasterSeal: STILL love SP :)
    November 24, 2018, 05:05:50 AM
  • ♦ Ninja ZX-10RR ♦: <3 aegersz
    September 13, 2018, 03:36:09 PM
  • aegersz: I STILL <3 LOVE SimplePortal
    September 13, 2018, 07:11:39 AM
  • aegersz: o LOVE you guys - Simple Portal rocks !
    May 09, 2018, 05:18:59 AM
  • Chen Zhen: our apologies for the site being down.. please read server issues topic
    March 22, 2018, 05:32:38 AM
  • {OCS}MasterSeal: LOL PLEASE forget I just posted that. I found the answer in my own dang post back in 2015. lol sorry!
    July 04, 2017, 10:47:55 PM
  • {OCS}MasterSeal: I know this SB isnt' for support, but I just have a general question. Who would I contact to find out where SP stores its block info? Is it DB driven or files? I searched the site but came up with nothing. probably my fault any insight is appreciated.
    July 04, 2017, 10:43:36 PM
  • ♦ Ninja ZX-10RR ♦: Excuse me but what does Simpleportal have to deal with that?
    February 05, 2017, 08:21:14 PM
  • WhiteEagle: of course IMHO that site appears to be dead :(
    February 04, 2017, 01:08:05 PM
  • WhiteEagle: If I can get that, then I'll use it for that site...
    February 04, 2017, 01:07:35 PM
  • WhiteEagle: decided to not use SMF for any projects, unless I can get a copy of the premium version of the fanfiction archive plugin
    February 04, 2017, 01:06:54 PM
  • expertdecisions: cloudflare
    January 28, 2017, 08:01:47 AM
  • aegersz: SM release 2.0.13 !
    January 12, 2017, 06:00:13 AM
  • raffo: Tks Emanuele, even if I didn't understand the fix :D
    November 07, 2016, 02:01:20 AM
  • emanuele: [link]
    November 01, 2016, 12:43:50 PM
  • emanuele: raffo: the English support board is a good place. ;)
    November 01, 2016, 12:43:38 PM
  • raffo: Where can I find the fix for the shoutbox?
    November 01, 2016, 05:06:09 AM
  • {OCS}MasterSeal: To the SP team, I make a point to come here and thank you as much as possible for your work.  so again, THANK YOU!
    October 28, 2016, 10:38:05 AM
  • emanuele: That's indeed funny, the limit is present only in the patch and not the full install.
    October 22, 2016, 06:14:58 PM

* Recent Posts

Adding Forums Button to Nav bar by jirapon
[August 01, 2019, 09:07:12 AM]


Re: Board Icons by ♦ Ninja ZX-10RR ♦
[July 30, 2019, 04:03:41 PM]


MOVED: Czech translation???? by ♦ Ninja ZX-10RR ♦
[July 30, 2019, 03:04:51 PM]


Board Icons by jirapon
[July 30, 2019, 07:28:44 AM]


Re: Thankyou Simpleportal, by ♦ Ninja ZX-10RR ♦
[July 29, 2019, 09:41:29 AM]

Blocks speak! Do you have an interest in getting more blocks - or even making your own? The Blocks Board is for you!

Author Topic: Chrome NULL terminator crashes pages  (Read 9457 times)

0 Members and 1 Guest are viewing this topic.

Offline Insanity01

  • Newbie
  • Posts: 2
Chrome NULL terminator crashes pages
« on: September 20, 2015, 01:34:30 PM »
You can crash chrome by going to the url: http://a/%%30%30
Furthermore, just hovering over such a URL will crash the tab. Now this is an issue in chromium and thus of little relevance to you. However, it does affect your forum engine in a larger way than I have found on other websites.

When you enter the following as your profile signature, we have some bad behaviour.
Code: [Select]
[img]http://a/%%30%30[/img]
After entering that as my profile picture, any page on which I had left a comment would crash. I get that this is kind of an issue in chromium, but it seems to me that having a check to make sure the URL does not contain a malicious string of this kind would be a good thing. I get why this happens - you probably send a GET request to the URL I have entered each time I load a page where I commented, which results in the rather unwanted behaviour. I also get that this problem *should* get fixed by the chromium developers but not everyone updates their browser!

Anyway, I just thought I'd leave this here, even if you guys decide to just wait untill it gets fixed in chromium!


Offline ♦ Ninja ZX-10RR ♦

  • Spammer Hammer
  • Support
  • *
  • Posts: 1193
  • Gender: Male
  • Sniper Legends
    • Virtual Interactive Games Entertainment™
  • SMF Version: 2.0.13
  • SP Version: 2.3.6
  • Elkarte Version: 1.0.6
Re: Chrome NULL terminator crashes pages
« Reply #1 on: September 20, 2015, 08:09:26 PM »
Insanity01,

Thank you for your report... I have to admit I was like "Huh?" when I was reading it and couldn't believe it until I actually hovered that link and saw Chrome crashing in front of me... Well, I sent them a rather angry feedback about it.
By the way it's not really a SimplePortal bug, and not even an SMF one. However, since it does affect the whole forum software itself, I'd say it should be addressed by the SMF devs, so that *everyone* can have a fix for that, because if we fix it on our end then only SimplePortal users will have it fixed.

Note: credits to BurkeKnight, it also crashes on Opera (because it's based on Chrome).

Regards
Have you tried SimplePortal Documentation before asking? ;)
F.A.Q.  English Support  |  Blocks Support
Fancy Feature idea ?!  |  Blocks Requests
Themes & Graphics

▼ My job! ▼

No PMs for support unless it's a paid request. Thank you! :)
#OpIsis

Offline Insanity01

  • Newbie
  • Posts: 2
Re: Chrome NULL terminator crashes pages
« Reply #2 on: September 20, 2015, 10:07:58 PM »
Insanity01,

Thank you for your report... I have to admit I was like "Huh?" when I was reading it and couldn't believe it until I actually hovered that link and saw Chrome crashing in front of me... Well, I sent them a rather angry feedback about it.
By the way it's not really a SimplePortal bug, and not even an SMF one. However, since it does affect the whole forum software itself, I'd say it should be addressed by the SMF devs, so that *everyone* can have a fix for that, because if we fix it on our end then only SimplePortal users will have it fixed.

Note: credits to BurkeKnight, it also crashes on Opera (because it's based on Chrome).

Regards

That's an error of my part, I wasn't sure where to post this. I figured either SP or SMF, and I opted for this one. But yes, it should be globally solved for people running the software.. Furthermore, I think that this might open the road for other security issues - as I don't have to hover over the link anymore to make it crash. Anyone opening a thread where I commented will just crash - without even my signature being seen by them. I'm not sure if this raises other security issues - but I will check this out a bit further and if I find any more things I can 'break' with this approach, I'll post it on SMF or here for sure.

Thanks for your feedback, and I hope this ends up at the right party to solve this issue.

Regards,

Dylan

Offline ♦ Ninja ZX-10RR ♦

  • Spammer Hammer
  • Support
  • *
  • Posts: 1193
  • Gender: Male
  • Sniper Legends
    • Virtual Interactive Games Entertainment™
  • SMF Version: 2.0.13
  • SP Version: 2.3.6
  • Elkarte Version: 1.0.6
Re: Chrome NULL terminator crashes pages
« Reply #3 on: September 21, 2015, 12:27:45 AM »
I posted it immediately on sm.org after you opened the topic already :) http://www.simplemachines.org/community/index.php?topic=539935.0

They will yell at you if you say there are security issues though :P I also think it can be somewhat annoying, but I don't get the insta-crash when I open this topic at least.

Regards
Have you tried SimplePortal Documentation before asking? ;)
F.A.Q.  English Support  |  Blocks Support
Fancy Feature idea ?!  |  Blocks Requests
Themes & Graphics

▼ My job! ▼

No PMs for support unless it's a paid request. Thank you! :)
#OpIsis

Offline ccbtimewiz

  • Hero Member
  • *****
  • Posts: 2185
  • Gender: Male
  • $("div.content:dd").hide();
  • SMF Version: None
  • SP Version: None
  • Elkarte Version: None
  • EhPortal Version: None
Re: Chrome NULL terminator crashes pages
« Reply #4 on: September 21, 2015, 05:40:38 PM »
You can add this into the word censors of your board:

Code: [Select]
http://a/%
This will prevent users from using the link at all in their signatures and posts.

You can also edit the parse_bbc function and modify how it produces URL, IMG, and IURL, if for whatever reason you don't want to use the board censors.

In /Sources/Subs.php

There are 6 instances.

Find:
Code: [Select]
$data = \'http://\' . $data;
Replace with:
Code: [Select]
$data = \'http://\' . $data;
$data = str_replace(array(\'http://a/%\', \'https://a/%\'), array(\'http://\', \'https://\'), $data);

However, this issue will most likely be fixed very soon by the Chrome developers according to this source.

Offline ♦ Ninja ZX-10RR ♦

  • Spammer Hammer
  • Support
  • *
  • Posts: 1193
  • Gender: Male
  • Sniper Legends
    • Virtual Interactive Games Entertainment™
  • SMF Version: 2.0.13
  • SP Version: 2.3.6
  • Elkarte Version: 1.0.6
Re: Chrome NULL terminator crashes pages
« Reply #5 on: September 21, 2015, 05:52:58 PM »
Nice, I had to login on Firefox to read the reply because it crashes even before opening the topic now. Yep Sayaka you can do that but I don't think it will work for all cases, it's not just that link at fault, I found others on the net.
Have you tried SimplePortal Documentation before asking? ;)
F.A.Q.  English Support  |  Blocks Support
Fancy Feature idea ?!  |  Blocks Requests
Themes & Graphics

▼ My job! ▼

No PMs for support unless it's a paid request. Thank you! :)
#OpIsis

Offline ccbtimewiz

  • Hero Member
  • *****
  • Posts: 2185
  • Gender: Male
  • $("div.content:dd").hide();
  • SMF Version: None
  • SP Version: None
  • Elkarte Version: None
  • EhPortal Version: None
Re: Chrome NULL terminator crashes pages
« Reply #6 on: September 25, 2015, 01:33:33 PM »
This is no longer a problem.

Offline ♦ Ninja ZX-10RR ♦

  • Spammer Hammer
  • Support
  • *
  • Posts: 1193
  • Gender: Male
  • Sniper Legends
    • Virtual Interactive Games Entertainment™
  • SMF Version: 2.0.13
  • SP Version: 2.3.6
  • Elkarte Version: 1.0.6
Re: Chrome NULL terminator crashes pages
« Reply #7 on: September 25, 2015, 10:24:46 PM »
Confirmed. I think I'll go ahead and mark this as solved since the Chrome devs fixed it.
Have you tried SimplePortal Documentation before asking? ;)
F.A.Q.  English Support  |  Blocks Support
Fancy Feature idea ?!  |  Blocks Requests
Themes & Graphics

▼ My job! ▼

No PMs for support unless it's a paid request. Thank you! :)
#OpIsis