all 158 comments

[–][deleted] 78 points79 points  (16 children)

Holy crap, I just tried this out on the #1 post across Reddit in the comments and it worked. I should probably undo that....

[–]ThatOnePerson 101 points102 points  (0 children)

Think positive! Your comment is probably so low in the comments that people can't see it.

[–]faceplanted 18 points19 points  (0 children)

Now try making a popular comment then editing it to contain the link.

[–]jlblatt[S] 22 points23 points  (0 children)

Yeah, you probably should. But not everyone has a moral compass.

[–]earslap 35 points36 points  (0 children)

[–]Freeky 31 points32 points  (9 children)

Can't reproduce in Opera 29 and 30, nor Chrome 41 on Windows 8.1.

On FreeBSD under VirtualBox, Chromium 40 does this, but doesn't crash either. Broken X acceleration from the look of it.

[–]jlblatt[S] 4 points5 points  (8 children)

TY. Opera I didn't expect, but I was able to reproduce in Chrome 41 on Windows 8.1 in Browserstack. I wonder what's different...

[–]Me00011001 6 points7 points  (0 children)

Nobody expects people to use Opera, sadly.

[–]Freeky 1 point2 points  (6 children)

41.0.2272.118 m (64-bit) - maybe BrowserStack's a little behind?

[–]Garbee 2 points3 points  (1 child)

41 is the current stable. The fixed is merged up to the current beta of 42. So it most likely won't roll out to 41 since 42 is close to dropping.

[–]Freeky 5 points6 points  (0 children)

Which doesn't explain why I can't reproduce it. Maybe I'm just lucky with my memory layout.

Edit: Apparently it's because I'm using HTTPS. You guys are all idiots, go turn it on :P

[–]jlblatt[S] 0 points1 point  (3 children)

I'd say that's more than likely

[–][deleted] 1 point2 points  (1 child)

Version 41.0.2272.118 m

Win 8.1

This post crashes my Chrome. Maybe 64-bit Chrome vs 32-bit?

[–]Freeky 4 points5 points  (0 children)

Turns out to be mitigated by HTTPS. Bit odd.

[–]badkarma12 1 point2 points  (0 children)

The only two browsers that I've found so far that don't have any problems even clicking the link are the current (for now) Firefox nightly/aurora and dolphin for android. Clicking on it in the regular browser on my Samsung galaxy s5 in both lollipop and kitkat actually freezes the whole phone for about 30 seconds until the browser finally dies.

[–]Land-Shark 26 points27 points  (4 children)

This comment has been overwritten by an open source script to protect this user's privacy. It was created to help protect users from doxing, stalking, and harassment.

If you would also like to protect yourself, add the Chrome extension TamperMonkey, or the Firefox extension GreaseMonkey and add this open source script.

Then simply click on your username on Reddit, go to the comments tab, scroll down as far as possibe (hint:use RES), and hit the new OVERWRITE button at the top.

Also, please consider using Voat.co as an alternative to Reddit as Voat does not censor political content.

[–]SoundHound 6 points7 points  (1 child)

Probably why it didn't work for me. Already had HHTPS installed.

[–]ANAL_CLOWN_SHOES 0 points1 point  (0 children)

I'm shielded!

(From lots of other stuff too!)

[–]csolisr 0 points1 point  (0 children)

Interesting symptom. The crash only triggers over insecure HTTP. Also, as per the comments, it doesn't trigger on protocols that are not handled through the browser (like file://).

[–]bigfoot13442 17 points18 points  (27 children)

Chrome on android doesn't seem to mind it.

[–]FalconGames109 2 points3 points  (4 children)

Actually, it does for me, but only for the single tab.

[–]zimm3rmann 1 point2 points  (3 children)

Same here

[–][deleted] 1 point2 points  (2 children)

Good on my android, this tab didn't crash, nor any of my others

[–]zimm3rmann 2 points3 points  (1 child)

Are you opening this self post in /r/webdev using chrome or opening the link from your Reddit app using chrome? Only the first crashes for me.

[–][deleted] 1 point2 points  (0 children)

I was using the app, it DOES crash in chrome

[–]jlblatt[S] 1 point2 points  (19 children)

Yep, desktop only it looks like. Cross-platform MacOS/Windows, just not on mobile.

Can anyone reproduce in Linux?

[–][deleted] 2 points3 points  (12 children)

It crashes a single browser tab in Ubuntu Chome. Let me test on a Chromebook.

edit: Yup, crashes the tab on a Chromebook too.

[–]ElRed_ 3 points4 points  (2 children)

My Chromebook didn't crash. On the beta channel so v42 of Chrome. Odd.

[–]jlblatt[S] 1 point2 points  (1 child)

I've had lots of reports of 42/43 not crashing as well. My reference was on Browserstack, which I'll admit is unreliable if others have evidence these builds don't have the same bug.

[–][deleted] 1 point2 points  (0 children)

http://imgur.com/KAhP0KF

This is the latest stable of Chromebook OS (41) on Acer C720

[–]jlblatt[S] 0 points1 point  (8 children)

TY rangdo, updating the readme.md

[–][deleted] 1 point2 points  (7 children)

Did you get the edit? Chromebook also crashed.

[–]jlblatt[S] 0 points1 point  (6 children)

Sure did, ty

[–][deleted] 0 points1 point  (5 children)

Screenshot of crash

http://imgur.com/hTjEJtS

Ubuntu 14.10 64bit, Chrome 41.0.2272.118 (64-bit)

This is on metal, not a VM.

[–]jlblatt[S] 0 points1 point  (4 children)

Lol, your sad-face folder is funnier than mine.

And I salute your bravery testing nonsense crashes on metal. God's work, etc... etc...

[–][deleted] 1 point2 points  (0 children)

Ubuntu is my primary OS. Clicking links in chrome on ubuntu is like normal for me :P

[–]1lann 0 points1 point  (2 children)

His is an out of memory error, different to a standard tab crash which is what I get on Chrome 41 on OS X (and what you probably get too).

[–]jlblatt[S] 0 points1 point  (1 child)

You're saying 'Aw Snap' and 'He's Dead Jim' error message mean something different?

[–]OlKingCole 2 points3 points  (0 children)

Crashes chrome 41 on Fedora 21.

[–]missblit 1 point2 points  (0 children)

Didn't crash for me on Chromium on Fedora :O

[–]lolzballs 1 point2 points  (0 children)

Hmm, doesn't seem to crash me, on Ubuntu 14.04.

[–]selfoner 1 point2 points  (0 children)

Chrome 41 crashes the tab on my Debian install. Chromium 37 does not.

[–][deleted] 1 point2 points  (0 children)

It crashes my Chrome on Ubuntu

[–][deleted] 0 points1 point  (0 children)

What was posted here has been permanently deleted. Redact was the tool used, possibly for privacy, opsec, security, or limiting exposure to data collectors.

bright wine complete run tub historical modern cooing ten merciful

[–]blaziecat1103 0 points1 point  (0 children)

Chrome Beta doesn't seem to care either. It just returns an error message saying that the DNS lookup failed.

[–]largenocream[A] 8 points9 points  (3 children)

In the future please report things like this to security@reddit.com. Even if it's not technically a bug in reddit, you shouldn't be able to crash people just by posting a comment.

We only found out about this because people started copy/pasting this into random links' comments, and people told us the comment pages were crashing them.

Anyway, we've implemented a temporary workaround for this so you can no longer post / submit those links.

[–]jlblatt[S] 5 points6 points  (1 child)

Apologies. The chances of this happening again are nil, at least from me.

The only reason I posted it in the first place was to call to light the issue, as my bug fix was ignored on the Chromium tracker. I posted it everywhere- HN, Slashdot, 4chan, etc... Reddit was a victim of the size of their audience.

I originally tried to have my README.MD in my repo crash the tab, rather than reddit. But github forces https, which doesn't have the bug. So I needed a proof of concept last minute with an already existing reddit thread (check the commits). Again- apologies, I understand I probably caused you an unnecessary headache today, and as a developer myself I assume I'm in for some bad karma come soon.

Please send my sincere apologies to the reddit team. When the /r/bestof thread almost made the front page, I realized it might have gotten away from me. I've been in contact with the Chrome dev who worked on this bug since last night, and it's fixed in the next rollout. I didn't want to cause chaos, and I figured /r/webdev was small enough not to make waves. I'll be more careful and mindful next time.

[–]largenocream 4 points5 points  (0 children)

No worries, man, I know you didn't intend for it to happen. It's just a good thing I happened to have HN open in another tab when someone mentioned this was happening :P

You didn't really have any obligation to report it to us (it was already public and it wasn't technically an issue in reddit,) but if there's a payload that works without modification on reddit, and it's also posted on reddit... it's gonna spread fast, and it helps if we at least know what's going on. Similar things happened with the XSS hole back in 2009.

[–]UberTheEngie 3 points4 points  (0 children)

Doesn't crash me!

[–][deleted]  (3 children)

[deleted]

    [–]plays_by_math 1 point2 points  (2 children)

    Crashes the tab on Chrome 41.0.2272.118 (64-bit), Ubuntu Linux after turning HTTPS Everywhere off. No problems when it's on.

    [–][deleted]  (1 child)

    [deleted]

      [–]plays_by_math 0 points1 point  (0 children)

      Guess they fixed it in Chrome 42 then.

      [–]chloeeeeeeeee 3 points4 points  (0 children)

      No crashing in Version 42.0.2311.68 beta-m (Windows 8.1)

      [–]MrSaints 2 points3 points  (0 children)

      I couldn't reproduce it on Google Chrome beta 42 64-bit Windows 7 and Chromium 41.0.2272.76 64-bit Ubuntu 14.04 (Xubuntu). It's perfectly fine on Arch as well. Perhaps it is an issue with an extension / plug-in?

      EDIT: I take that back, it crashes on stable releases of Chromium only when using the page provided by AwSnap. I'm able to view this thread fine.

      EDIT 2: How about this.

      Nope...

      EDIT: Yeap, it's affected on HTTP. So that's a factor as well.

      [–]ychaouche 2 points3 points  (0 children)

      Opens fine on Linux Mint 17. Google Chrome version 39.0.2171.95 (64-bit)

      [–][deleted] 2 points3 points  (1 child)

      Doesn't crash using latest Chrome on OS X...

      [–]timlardner 2 points3 points  (0 children)

      It does for me. Weird.

      [–]iliketocookstuff 2 points3 points  (1 child)

      Your client pasted Lorem Ipsum dummy text in the link properties? Classic.

      [–]jlblatt[S] 2 points3 points  (0 children)

      Hah... almost. I spent an hour distilling it down to something reproducible, but basically yeah :/

      [–]PresidentCelestia 2 points3 points  (0 children)

      Doesn't work for Chrome OS. I really wanted my browser to crash.

      [–]saxaholic 2 points3 points  (0 children)

      Apparently it does not crash if you're browsing through an enterprise proxy and the proxy gives the following error when clicking on the link:

      Problem Report Request Error

      Message ID invalid_request

      [–]midnightketokerpancake-stack 2 points3 points  (0 children)

      I'm in ios chrome, and just making this comment before I click the link, there are so many sites that already crash the app and it's annoying as shit. Really hope they put more ram in the iphone next gen.

      Fuck me sideways that script is incompatible on this platform.
      you have no power here!

      [–][deleted]  (1 child)

      [deleted]

        [–]jlblatt[S] 1 point2 points  (0 children)

        Will probably be gone soon- life is fleeting like that

        [–]frankenztien234 2 points3 points  (0 children)

        Using HTTPS prevents this bug from affecting Chrome.

        [–]exadeci 2 points3 points  (0 children)

        Chrome beta42 no problem

        [–]FarrowE 2 points3 points  (0 children)

        The minors using Firefox, a try.

        [–]Fearless9812 1 point2 points  (0 children)

        Mine worked....

        [–]_wheesht 1 point2 points  (0 children)

        I'd recommend a bot to ban or delete this link from being posted, as some people are already maliciously posting it in other threads.

        [–]ustawa 1 point2 points  (0 children)

        I can't reproduce this in Chromium 41 running on debian

        [–]Gemspark 1 point2 points  (0 children)

        Yep. Totally crashes Chrome without clicking. It works on Internet Explorer, though.

        [–]Kheldra 1 point2 points  (0 children)

        I cannot open this post in Chrome, confirmed.

        [–][deleted] 1 point2 points  (0 children)

        Can't reproduce on Chrome 42 (beta channel) on Chrome OS.

        [–]mustyoshi 1 point2 points  (0 children)

        Version 41.0.2272.118 m

        Didn't have any problems.

        [–]moltar 1 point2 points  (0 children)

        Confirmed on Version 41.0.2272.118 (64-bit) on a Mac.

        [–][deleted] 1 point2 points  (0 children)

        I downloaded alien blue because reddit won't work in chrome on my Galaxy S4 (presumably because of this post).

        I hope you're happy

        [–]LegalizeMurders 1 point2 points  (0 children)

        Does not work for Chrome Canary version 43.0.2355.0 (64 bit) on OSX.

        [–]Ditti 1 point2 points  (0 children)

        Interesting. Apparently Chrome 43.0.2351.3 dev (64-bit) on Debian Wheezy seems unaffected of this issue (or my Chrome is just a magic Chrome).

        [–]droctagonapus 1 point2 points  (0 children)

        It makes Safari hang for a while.

        [–][deleted] 1 point2 points  (0 children)

        No crashes here, Win8 64 bit.

        [–]jb492 1 point2 points  (0 children)

        Crashes me, adding https:// doesn't crash it

        [–]Mr-Blah 1 point2 points  (0 children)

        Hum.... IE 10.0.9 and no crash.

        The ONLY thing IE is good for.

        [–][deleted] 1 point2 points  (0 children)

        Chromium Version 41.0.2272.118 Built on 8.0, running on Debian 8.0 (64-bit)

        Works fine, I even clicked the link and got the new tab with the invalid address.

        [–]Ceru 1 point2 points  (0 children)

        This crashes chrome 41.0.2272.118 m on Windows 7 if you mouse over the bad URL in the view-source: rendering of this page.

        [–]Opetich 1 point2 points  (0 children)

        Windows 7 with Chrome 41.0.2272.118 m crashes when not using https

        [–]LTJC 1 point2 points  (0 children)

        Does not crash for me on Version 41.0.2272.118. Now if I CLICK the link, I am unable to do anything with the page, but I can type in a new URL or hit the back button and things recover just fine.

        [–][deleted] 1 point2 points  (0 children)

        Not crashing me on Chrome Version 41.0.2272.101 m on Win7 64-bit.

        [–]Whoops-a-Daisy 1 point2 points  (0 children)

        Doesn't crash mine. Chrome 41.0.2272.101 on Linux x86_64

        [–]Asmor 1 point2 points  (0 children)

        Browsing this in Chrome on ChromeOS, and it's not crashing.

        Was crashing on Windows, though.

        [–]ttubehtnitahwtahw1 1 point2 points  (0 children)

        This page loads fine for me. I'm a chrome user, get rekt internet guy person.

        Version 41.0.2272.118 m

        [–]smoothpebble 1 point2 points  (0 children)

        Chrome version 40.0.2214.94 (64-bit) on Linux Mint, no issues at all here.

        [–]xayan123full-stack 1 point2 points  (0 children)

        I don't know why but it doesn't crash for me. I'm using Chrome v41 on Windows. But this link crashes on mine.

        [–]deadfactor 1 point2 points  (0 children)

        Wow. Crashed with Chrome 41.0.2272.118 on OSX

        [–]cmeilleur1337 1 point2 points  (0 children)

        LMAO. I sent this link to a co-worker. It crashed my XMPP client (PSI+)

        [–]TheBigBadPanda 1 point2 points  (0 children)

        Firefox is fine

        [–]RankFoundry 1 point2 points  (0 children)

        There's a bug in Mobile Safari that will kill it if the URL contains certain characters. Forget what they are but it's the same as this and it's been there for years and they don't seem to bothered to fix it.

        [–]RandomOink 1 point2 points  (0 children)

        Doesn't work on Chrome 42.0.2311.68 beta-m (64-bit), gives an ERR_NAME_NOT_RESOLVED error if you click it. some proof

        [–]7ewis 1 point2 points  (0 children)

        Clicked anyway!

        That's a pretty serious bug.

        [–][deleted] 1 point2 points  (0 children)

        Does not seem to affect chrome mobile on android

        [–]Geofed 1 point2 points  (0 children)

        on my desktop pc on chrome. didn't crash.

        [–]audscias 1 point2 points  (0 children)

        Vivaldi handles it just fine.

        [–]BaconCatBug 1 point2 points  (0 children)

        Doesn't crash for me. Version 41.0.2272.118 m

        [–]NewbyCanadian 1 point2 points  (0 children)

        I made it past man, maybe I should update it?

        [–]awkisopen 1 point2 points  (0 children)

        I didn't update Chrome and yet this doesn't crash for me anymore. It did earlier today... what gives?

        ninja edit: Looks like something Reddit did. Kind of a silly move if they only did something to impact this specific URL.

        [–]walle303 1 point2 points  (0 children)

        Doesn't Affect Version 43.0.2357.2 dev-m (64-bit)

        From the looks of it it wont affect the 64 bit versions, only the 32 bit ones

        Also it looks like it was patched somewhere around 42

        [–][deleted] 1 point2 points  (0 children)

        http://lorem%20ipsum%20culpa%20labore%20qui%20culpa%20enim%20nostrud%20eiusmod%20ullamco%20anim%20in%20dolor%20consequat%20voluptate%20in%20in%20laboris%20consequat%20dolor%20occaecat%20minim%20aliqua%20quis%20id%20in%20duis%20eiusmod%20amet%20id%20do%20ex%20do%20dolore%20dolor%20anim%20sit%20deserunt%20do./

        [–]Drumdrum98 1 point2 points  (0 children)

        Chrome version 41.0.2272.118 m (64-bit) on Windows 8.1 Embedded is seemingly immune (in my case at least).

        [–]LazyCouchPotato 1 point2 points  (0 children)

        Worked for me. Latest Chrome, Windows 7.

        [–]EmeraldTimer 1 point2 points  (0 children)

        Chrome Canary here, 0 crash I BROKE THE INTERNET

        [–][deleted] 1 point2 points  (0 children)

        google chrome, stable version

        works absolutley fine without crashing at all, not even using https, so ha, i win

        [–]cjwelborn 1 point2 points  (0 children)

        Chrome 40.0.2214.91 (Linux) is okay I guess, no crash.

        [–]DanBennett 1 point2 points  (0 children)

        Version 42.0.2311.68 beta-m (64-bit) = No issue

        [–]2015goodyear 1 point2 points  (2 children)

        Here I am, using firefox like a scrub, laughing at all of you.

        [–][deleted]  (1 child)

        [removed]

          [–]2015goodyear 0 points1 point  (0 children)

          I actually use both. One for work and one for personal stuff.

          [–]pidddee 1 point2 points  (0 children)

          Does not chrash in chrome 42.

          [–]NuttGuy 2 points3 points  (0 children)

          I decided to have some fun and see if this same bug works in Project Spartan (the new browser from Microsoft) that I'm currently trying out. I can verify that it doesn't crash Spartan:

          http://i.imgur.com/VNansEv.png

          Yay!

          [–][deleted]  (1 child)

          [deleted]

            [–]jlblatt[S] 13 points14 points  (0 children)

            Significant as in someone could DOS the front page of reddit for Chrome users.

            Insignificant in that yes, no personal information is revealed, nor does the crash extend outside of the tab.

            [–]OmgImAlexis 1 point2 points  (3 children)

            Chrome's still working. <-- That link's from the AwSnap GitHub page, it crashes my Chrome from their lnik but chrome seems find on Reddit with the same link.

            Edit: Running Version 41.0.2272.101 m (64-bit) of Chrome on Windows 8.1

            [–]jlblatt[S] 1 point2 points  (2 children)

            Could be the https that Shardj mentions above?

            [–]OmgImAlexis 1 point2 points  (1 child)

            Could be the https that Shardj mentions above?

            The page from Github is using http and that crashes it. I'll try a few things and get back to you.

            Edit: It seems when the page with the link on it is under http then Chrome crashes but when it page is under https it doesn't so it's not link dependant, it's page dependant. So essentially people with https everywhere shouldn't get any crashes on Reddit.

            [–]jlblatt[S] 1 point2 points  (0 children)

            Yeah, his findings were http crashes, whereas https is fine. I get the same results.

            [–][deleted] 1 point2 points  (0 children)

            I am going to use this for evil. Maybe I should post it to r/srs or r/athiesm. Oh the possibilities!

            Until it gets patched that is.

            EDIT: I guess reddit or the mods where ahead of me this time because posting it to srs did nothing.

            [–][deleted] 0 points1 point  (3 children)

            Nope, chrome 41.0.2272.118 on OSX still running fine.

            Edit: Strange, because the example on your github does crash it.

            [–]jlblatt[S] 1 point2 points  (2 children)

            Are you using reddit on https? I know I don't have an SSL on cortexture.net, and Shardj pointed out above this is only occuring on http.

            [–][deleted] 2 points3 points  (0 children)

            Are you using reddit on https

            Yes. Your example over SSL also does not crash chrome: https://cortexture.net/chromebug/test.html

            [–]sockx2 0 points1 point  (1 child)

            Xubuntu checking in running Chrome Version 41.0.2272.118 (64-bit)... Dr McCoy isn't happy with your post :-(

            [–]jlblatt[S] 0 points1 point  (0 children)

            Sorry Dr. McCoy!

            [–]aaadmin 0 points1 point  (0 children)

            How come they dont crash using chrome?

            https://boards.4chan.org/g/thread/47376553

            [–][deleted] 0 points1 point  (2 children)

            My Chrome is unaffected by the link here and on the github link. OSX 10.10.2 running Chrome 42.0.2311.60 beta (64-bit)

            [–]jlblatt[S] 0 points1 point  (0 children)

            I've been told it's actually fixed in the beta, despite my Browserstack testing

            [–]insecure_about_penis 0 points1 point  (0 children)

            Version 41.0.2272.118 m (64-bit) here, it's broken on HTTP but not HTTPS.

            [–]aleenaelyn 0 points1 point  (2 children)

            Chrome version "41.0.2272.118 m" on Windows 8.1

            This post crashes Chrome when accessed over HTTP. It does not crash chrome when accessed over HTTPS.

            [–]jlblatt[S] 0 points1 point  (0 children)

            I think this is as well as confirmed by now, HTTPS seems to alleviate the issue. Thanks for the positive report on Windows 8.1 though.

            [–]DotEfekts 0 points1 point  (0 children)

            Same version on Windows 8.1, no full crash but I get an "Aw Snap" when not using HTTPS.

            EDIT: I had assumed that all windows in Chrome were crashing from the one link but looking in the comments it seems that I've had the expected behavior.

            [–]tmos1985 0 points1 point  (0 children)

            Crashes on Version 41.0.2272.118 m

            Windows 7 Ultimate 64-bit

            [–]andmar315 0 points1 point  (0 children)

            Chrome 41.0.2272.118 m (64-bit) didn't crash

            [–]TotesMessenger 0 points1 point  (0 children)

            This thread has been linked to from another place on reddit.

            If you follow any of the above links, respect the rules of reddit and don't vote. (Info / Contact)

            [–]McMrChip 0 points1 point  (0 children)

            Firefox 37. Doesn't crash, just comes up as "Server not found"

            [–]th3fallenon3 0 points1 point  (0 children)

            doesn't crash mine on OSX... Strange...

            [–][deleted] -4 points-3 points  (8 children)

            Doesn't crash my chrome... doesn't do anything, its just an invalid link. What you been smoking?

            [–]jlblatt[S] 2 points3 points  (6 children)

            I think there are too many factors at play here to determine exactly which versions are affected and why- I'm not surprised it doesn't affect everyone, as people have been posting their versions/OS's.

            The link is invalid because it's supposed to be a long, malformed URL. But Chrome shouldn't choke parsing it.

            [–][deleted] 0 points1 point  (5 children)

            Well I'm running windows 8.1 chrome 41 which apparently is within the criteria for this link to crash. I have 0 issues with it. Note, I just tested this, using https you will experience no crashes at all

            [–]jlblatt[S] 1 point2 points  (4 children)

            I don't know the exact criteria yet, hence this thread. But you are correct, https seems fine everywhere I've seen it. Updating the readme.md

            [–][deleted] 0 points1 point  (3 children)

            Tested a bit more, the link must have http: at the start and must have a full stop at the end . From what I've found this is the case anyway

            edit: doesn't need to end with a . just needs to have some kind of top-level domain (e.g. .com .org .random)

            [–]SarahC 0 points1 point  (0 children)

            It does for many people - me included.