Breaking News

Sigma Unveils 200mm f/2 DG OS Sports and 12mm F/1.4 DC lens SSSTC Launches World's First Industrial M.2 SSD Featuring KIOXIA’s 8th generation BiCS and PCIe 5.0 Interface Lexar presents new products at Gamescom 2025 Samsung Introduces Galaxy Buds3 FE Samsung Expands Super Big TV Lineup with 115-Inch Neo QLED 4K TV

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

HTML5 Weakness Allows Data Dump On Hard disks

HTML5 Weakness Allows Data Dump On Hard disks

Enterprise & IT Mar 1,2013 0

A developer has discovered a loophole in the HTML5 web code, which could allow gigabytes of junk data to be dumped on your hard disks. Developer Faross Aboukhadijeh found the bug and set up a demo page (FillDisk.com) as a proof-of-concept, which that fills visitors hard drives with pictures of cartoon cats.

The HTML5 Web Storage standard was developed to allow sites to store larger amounts of data (10 MB) than was previously allowed by cookies (4KB). The standard anticipated that sites might abuse this feature and advised that browsers limit the total amount of storage space that each origin could use. So currently, Google Chrome limits the amount of data to 2.5 MB per origin, Mozilla Firefox and Opera alllows up to 5 MB per origin and Internet Explorer up to 10 MB per origin. In addition, the web standard says that HTML 5 user agents should guard against sites storing data under the origins other affiliated sites, a move that would not allow for circumventing the storage limits.

However, Chrome, Safari, and IE currently do not implement any such "affiliated site" storage limit. Thus, cleverly coded websites, like FillDisk.com, have effectively unlimited storage space on visitor?s computers.

The proof-of-concept page fills up the user?s hard disk on Chrome, Safari (iOS and desktop), Opera, and IE. The page has been tested to work with Chrome 25, Safari 6, Opera (12), IE 10. The page does not work on Firefox, since Firefox?s implementation of localStorage is smarter, said Mr Aboukhadijeh.

In a bid to solve the problem, bug reports about the exploit have been filed with major browser makers.

Tags: HTML5
Previous Post
Facebook To Unveil New New Newsfeed
Next Post
Research Found That SSDs Suffer Data Loss When They Lose Power

Related Posts

  • YouTube Now Defaults to HTML5

  • HTML5 is Specs Finalized

  • Netflix To Implement HTML5 Video Technologies

  • Intel Expands Support of HTML5 with Launch of App Development Environment

  • HTML5 Definition Complete, W3C Moves to Interoperability Testing and Performance

  • Adobe Web dev Embraces HTML5 Wed Development

  • Intel Focuses On Software Developers, Announces New HTML5 Tools

  • Adobe Eliminates Flash Player For Mobiles, Sees Future In HTML5

Latest News

Sigma Unveils 200mm f/2 DG OS Sports and 12mm F/1.4 DC lens
Cameras

Sigma Unveils 200mm f/2 DG OS Sports and 12mm F/1.4 DC lens

SSSTC Launches World's First Industrial M.2 SSD Featuring KIOXIA’s 8th generation BiCS and PCIe 5.0 Interface
Enterprise & IT

SSSTC Launches World's First Industrial M.2 SSD Featuring KIOXIA’s 8th generation BiCS and PCIe 5.0 Interface

Lexar presents new products at Gamescom 2025
PC components

Lexar presents new products at Gamescom 2025

Samsung Introduces Galaxy Buds3 FE
Smartphones

Samsung Introduces Galaxy Buds3 FE

Samsung Expands Super Big TV Lineup with 115-Inch Neo QLED 4K TV
Consumer Electronics

Samsung Expands Super Big TV Lineup with 115-Inch Neo QLED 4K TV

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

be quiet! Pure Base 501

be quiet! Pure Base 501

Terramaster F8-SSD

Terramaster F8-SSD

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed