What the Internet knows about you
[Posted September 2, 2009 by corbet]
A new site at
whattheinternetknowsaboutyou.com
is an interesting demonstration of CSS-related browser history disclosure
vulnerabilities. This site is able to produce a surprisingly comprehensive
list of sites that one has visited, down to the level of specific pages on
social networking sites and such. No JavaScript required. There's also
information on just how the
site works and how the disclosure of information can be minimized.
"
It is a source of amazement to us that such an obvious and
well-documented history sniffing channel has been allowed to exist for so
many years. We cannot help but wonder why, despite all the malicious
potential, such a hole has not yet been closed."
(
Log in to post comments)