• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

HTML5 exploit

Joined
Sep 1, 2010
Messages
7,023 (1.41/day)
Web developer Feross Aboukhadijeh created FillDisk.com in order to demonstrate the exploit in HTML5. The Web Storage standard used in HTML5 allows any website to place large amounts of data on your computer’s drive, which could result in a lot of frustration as the user will probably continually wonder why their hard drives are completely out of disk space.

Web browsers have the ability to limit just how much space websites can dump onto your hard drive, with Mozilla Firefox being able to intelligently know how much a website should be loading onto the hard disk at a time. Other browsers, such as Chrome, IE, Safari and Opera currently have no storage limits, although we hope now that this exploit has been publicized, the developers of these web browsers would look into patching their software so our computer hard disks can stay from being clogged up with junk data.

Sounds nasty

 
Last edited by a moderator:
Joined
Nov 16, 2007
Messages
1,166 (0.19/day)
Location
Hampton Roads
Processor Xeon x5650
Motherboard SABERTOOTH X58
Cooling Fans
Memory 24 GB Kingston HyperX 1600
Video Card(s) GTX 1060 3GB
Storage small ssd
Display(s) Dell 2001F, BenQ short throw
Case Lian Li
Audio Device(s) onboard
Power Supply X750
Software Mint 19.3, Win 10
Benchmark Scores not so fast...
Firefox is king again!
 

Krazy Owl

New Member
Joined
Jan 12, 2012
Messages
897 (0.20/day)
Location
Montreal
System Name HTPC-Cube
Processor AMD Athlon 64 skt754 3200+ 1M cache
Motherboard Foxconn Winfast K8S760MG-6LRS
Cooling Stock
Memory 2 gigs DDR400
Video Card(s) HIS IceQ 4670 AGP 1gig DDR3
Storage White label 80gigs sata
Display(s) Polaroid 19 inches 1366X768 LED
Case Chenming cube
Audio Device(s) Onboard
Power Supply Raidmax RX-500S
Software Seven Pro 64bits
What about Google chrome compared to firefox vs explorer.... is google chrome safe too ?
 
Joined
May 27, 2008
Messages
3,628 (0.62/day)
System Name Ultra 64
Processor NEC VR4300 (MIPS R4300i)
Motherboard proprietary design
Cooling Fanless aircooled
Memory 4.5MB 250 MHz RDRAM
Video Card(s) 62.5 MHz Reality Coprocessor
Storage 32 - 512 Mbit ROM Cartridge
Display(s) 720x576
Case Clear Blue Funtastic
Audio Device(s) 16-bit CD quality
Power Supply proprietary design
Mouse N64 mouse for use with N64DD
Keyboard N64 keyboard for use with N64DD
Joined
Jul 5, 2008
Messages
272 (0.05/day)
System Name WorkStation
Processor Intel i7 3770k @ 4.4GHz
Motherboard ASRock Z77 Extreme6
Cooling Corsair H110 Water Cooler AIO
Memory Corsair Vengeance 8GB DDR3 1600MHz
Video Card(s) MSI GTX680 Twin Frozr III OC
Storage WD 1TB Sata III
Display(s) Samsung 22-inch LED 1080p
Case Corsair Carbide Air 540
Audio Device(s) Onboard Realtek 898 HD
Power Supply Corsair CS750M Gold
Software Windows 8.1 Pro x64
Why would anyone dump data from their website? and loose bandwidth... its not free you know...
 
Joined
May 27, 2008
Messages
3,628 (0.62/day)
System Name Ultra 64
Processor NEC VR4300 (MIPS R4300i)
Motherboard proprietary design
Cooling Fanless aircooled
Memory 4.5MB 250 MHz RDRAM
Video Card(s) 62.5 MHz Reality Coprocessor
Storage 32 - 512 Mbit ROM Cartridge
Display(s) 720x576
Case Clear Blue Funtastic
Audio Device(s) 16-bit CD quality
Power Supply proprietary design
Mouse N64 mouse for use with N64DD
Keyboard N64 keyboard for use with N64DD
Maybe who ever it is that developed HTML 5 thought the same and that's why it got overlooked?
 
Joined
Nov 10, 2006
Messages
4,665 (0.73/day)
Location
Washington, US
System Name Rainbow
Processor Intel Core i7 8700k
Motherboard MSI MPG Z390M GAMING EDGE AC
Cooling Corsair H115i, 2x Noctua NF-A14 industrialPPC-3000 PWM
Memory G. Skill TridentZ RGB 4x8GB (F4-3600C16Q-32GTZR)
Video Card(s) ZOTAC GeForce RTX 3090 Trinity
Storage 2x Samsung 950 Pro 256GB | 2xHGST Deskstar 4TB 7.2K
Display(s) Samsung C27HG70
Case Xigmatek Aquila
Power Supply Seasonic 760W SS-760XP
Mouse Razer Deathadder 2013
Keyboard Corsair Vengeance K95
Software Windows 10 Pro
Benchmark Scores 4 trillion points in GmailMark, over 144 FPS 2K Facebook Scrolling (Extreme Quality preset)
The HTML5 standard DOES NOT allow this. The fault isn't with HTML5, the fault is with IE, Chrome, Safari, Opera, and Firefox for not implementing it properly.

Why would anyone dump data from their website? and loose bandwidth... its not free you know...

They're probably pulling it from cache.
 
Top