Status: Unconfirmed
Owner: ----
Labels: Type-Bug Pri-2 OS-All Area-Misc

New issue 20448 by dionyziz: Client-side denial of service using  
application-request prompts
http://code.google.com/p/chromium/issues/detail?id=20448

Chrome Version       : 3.0.195.6
URLs (if applicable) : http://niggers.on.nimp.org/
Other browsers tested:
   Add OK or FAIL after other browsers where you have tested this issue:
      Safari 4: FAIL
   Firefox 3.x: FAIL
          IE 7: FAIL
          IE 8: FAIL

What steps will reproduce the problem?
1. Go to http://www.lastmeasure.com/mirrors.php
2. Click on a mirror

What is the expected result?
The particular web page should open and display its content as expected,
including launching the Java applications and playing the plug-in sounds.
The pop-up windows should be blocked, the application starting requests
should be prompted to the user.

The application prompting Window needs to display a "Do not allow this web
site to display more alerts." checkbox. The user should retain the ability
to close the tab and open the Chrome menu to start the task manager.

What happens instead?
The particular web page opens correctly and displays content. Java and
plug-ins function correctly. Pop-up windows are blocked as expected. The
user is flooded with application starting requests that they are not able
to close. They cannot close the particular tab, or open up the Chrome menu
to start the Chrome task manager. The web-page results in a client-side
Denial of Service.


Please provide any additional information below. Attach a screenshot if
possible.


--
You received this message because you are listed in the owner
or CC fields of this issue, or because you starred this issue.
You may adjust your issue notification preferences at:
http://code.google.com/hosting/settings

--~--~---------~--~----~------------~-------~--~----~
Automated mail from issue updates at http://crbug.com/
Subscription options: http://groups.google.com/group/chromium-bugs
-~----------~----~----~----~------~----~------~--~---

Reply via email to