4 ms·
Now I'm half tempted to serve up ads from a path in the form '/a{n}b/\d+' with sufficiently large n to bring the O(mn) std::string::find subpattern matcher to a
by kbwt 9y ago
Now I'm half tempted to serve up ads from a path in the form '/a{n}b/\d+' with sufficiently large n to bring the O(mn) std::string::find subpattern matcher to a crawl when it encounters my harmless 'src="/a{m}"' iframes. Preferably n > 32K/2 to blow through L1 cache.
- kodablah 9y agoWhich code are you looking at? I see it uses https://cs.chromium.org/chromium/src/components/url_pattern_index/url_pattern_index.h https://cs.chromium.org/chromium/src/components/url_pattern_.... Also, from what I gather from their docs, this is only for the ad-block-filter formatted lists. For their own super-secret-better-ads list, they use safe browsing lists which use a hash-some-then-phone-home approach IIRC [0]. I mean, even Mozilla that uses the safe browsing lists says at [1] that the internal documentation [2] is only available under NDA. 0 - https://developers.google.com/safe-browsing/v4/local-databases https://developers.google.com/safe-browsing/v4/local-databas... 1 - https://wiki.mozilla.org/Security/Safe_Browsing https://wiki.mozilla.org/Security/Safe_Browsing 2 - https://mana.mozilla.org/wiki/display/FIREFOX/Safe+Browsing https://mana.mozilla.org/wiki/display/FIREFOX/Safe+Browsing
- kbwt 9y agoThis is the call stack I'm looking at: #0 https://cs.chromium.org/chromium/src/components/url_pattern_index/url_pattern.cc?l=93 https://cs.chromium.org/chromium/src/components/url_pattern_... #1 https://cs.chromium.org/chromium/src/components/url_pattern_index/url_pattern.cc?l=227 https://cs.chromium.org/chromium/src/components/url_pattern_... #2 https://cs.chromium.org/chromium/src/components/url_pattern_index/url_pattern_index.cc?l=595 https://cs.chromium.org/chromium/src/components/url_pattern_... #3 https://cs.chromium.org/chromium/src/components/url_pattern_index/url_pattern_index.cc?l=653 https://cs.chromium.org/chromium/src/components/url_pattern_...
- kodablah 9y agoAh, I didn't dig, but I'd contend that URL length limits would apply and the worst you could do is slow down a client's browser in the same way you could just by multiplying the number of attempted requests to a blockable URL.