The Slash That Flagged the Whole Web — JavaScript Bug Hunt

Modelled on Google's 2009 malware-warning incident: a single / was accidentally added to the list of dangerous URL patterns.

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Easy
  • Concepts: Data Validation, Substring Matching
  • Modelled on: Google Safe Browsing · 2009
  • Visible tests: a genuine pattern still blocks; a lone slash does not flag the web
  • Reward: 50 XP for a complete fix

Briefing

Modelled on Google's 2009 malware-warning incident: a single / was accidentally added to the list of dangerous URL patterns. Because every URL contains a slash, the warning "This site may harm your computer" appeared on every result on the web for about 40 minutes.

blocklist.js matches URLs against patterns by substring. It has no guard against a pattern that matches everything.

Fix isBlocked so degenerate patterns cannot flag every URL.

Bug report

BUG-SAFEBROWSE · Priority: Critical · Reported by: search quality

isBlocked(url, patterns) should return true only when the URL genuinely matches a meaningful pattern.

Observed: an operator typo added "/" to the list. Every single URL now matches. Empty strings behave the same way.

Logs

[safebrowsing] flagged 100% of results in this batch (n=4821)
[safebrowsing] active patterns: ["evil.example", "/", ""]

The code as shipped

src/safety/blocklist.js (editable)

// Returns true when the URL matches any blocklist pattern.
exports.isBlocked = function (url, patterns) {
  for (var i = 0; i < patterns.length; i++) {
    if (url.indexOf(patterns[i]) !== -1) return true;
  }
  return false;
};

Read-only context: src/safety/RULES.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.