Safari Proxy Settings can act as Denial of Service

Posted by Jonathan

According to this mail on full-disclosure, Safari’s behavior can be seen as a Denial of Service attack on your proxy server if you configure a proxy PAC file in Tiger’s System Preferences.

Safari tries to fetch the PAC file many times for each page browsed. That can lead to a high load on your proxy, presumably leading to a crash if many browsers are configured to use the PAC file.

UPDATE:
See a follow-up mail on full-disclosure for more information.