Closed Bug 304270 Opened 19 years ago Closed 19 years ago

java/javascript drawing routines on this site draw into other tabs

Categories

(Firefox :: Tabbed Browser, defect)

PowerPC
macOS
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 162134

People

(Reporter: heywoodj123, Unassigned)

References

()

Details

Attachments

(1 file)

User-Agent:       Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.8b3) Gecko/20050712 Firefox/1.0+
Build Identifier: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.8b3) Gecko/20050712 Firefox/1.0+

Was watching a live chess game on the caissa.com site in one tab, opened a (new)
second tab, pointed it to google.com. Google main page loaded normally. After a
few seconds -- without my doing anything! -- part of the chessboard from the
first tab (which was not focused) overwrote the google tab I was looking at.

If this can be done in a controllable and repeatable way, I suppose it could
potentially be a serious security risk (in the case of a phishing or
cross-site-scripting attack).

Reproducible: Always

Steps to Reproduce:
1. Go to caissa.com, log in (14-day trial registration is free; as of 11aug2005
there is an account with U/P=deerparkalpha2/javascriptbug), and from the main
menu, select "Watch" under "Play a live game" (orange section).

2. Pick any of the listed active games and click on either player's handle.

3. Open a new tab, point it at some unrelated page (e.g. www.mozilla.org), and wait.

Actual Results:  
As soon as a move is made in the game, the java applet will draw into whatever
tab happens to be open. To force this, go to the tab where the live game is
shown, click on the |< icon (rewinds game to first move) and then the > icon
(replays the game, move by move, with a 2-second delay between each). Now change
focus to any other tab and wait.

Expected Results:  
Uh, like, not drawn into tabs other than the one in which it was displaying the
game. Also, keyboard input into forms on the tab being overwritten stops working
temporarily in some cases; this persists until the chess game tab is stopped or
closed.

I will attach a screenshot of this effect overwriting the google main page shortly.

Leaving severity/security settings at defaults (normal/no) for now; feel free to
change as appropriate.
In the screenshot there are about a dozen tabs open, but I can reproduce this
problem with just two tabs -- so the number doesn't seem to matter.
Please check at least the list of most frequently reported bugs before filing a 
new one, this is #2 on that list.

*** This bug has been marked as a duplicate of 162134 ***
Status: UNCONFIRMED → RESOLVED
Closed: 19 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: