+ Reply to Thread
Results 1 to 6 of 6

Thread: Your history revealed

  1. #1
    Advanced User Renk's Avatar
    Join Date
    17.08.08
    Location
    Elsewhere
    P2P Client
    utorrent
    Posts
    581
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss581

    Exclamation Your history revealed

    Stealing your history...
    ...without Javascript!

    My previous demo of sniffing a user's history was pretty effective. However, a lot of people commented on it not working with NoScript, naturally. So, I set to work to create a version that does work even if you have NoScript enabled. If the previous version didn't shock you, this one ought to.

    Sniffing Browser History with NO Javascript!
    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    Mihai (13.09.09) , Grambo (16.06.09) , anonftw (15.06.09) , anon (14.06.09)

  3. #2
    Advanced User Renk's Avatar
    Join Date
    17.08.08
    Location
    Elsewhere
    P2P Client
    utorrent
    Posts
    581
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss581
    The link I gave don't work anymore.


    Here is an other:

    What the Internet knows about you

    But I don't now at this momment what kind of hole it uses.
    Reply With QuoteReply With Quote
    Thanks

  4. #3
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,439
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39439
    Seems it uses both JS and CSS attacks, there's more info here:
    http://whattheinternetknowsaboutyou....s/details.html
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  5. #4
    Moderator
    shoulder's Avatar
    Join Date
    12.04.08
    Location
    I*** D* M*****
    Posts
    4,827
    Activity Longevity
    3/20 19/20
    Today Posts
    0/5 sssss4827
    So this isn't using any new "bug", therefore nothing to fear for.



    ------------------------------>>>>>>>>>> <<<<<<<<<<------------------------------

    Reply With QuoteReply With Quote
    Thanks

  6. #5
    Advanced User Renk's Avatar
    Join Date
    17.08.08
    Location
    Elsewhere
    P2P Client
    utorrent
    Posts
    581
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss581

    Talking

    Quote Originally Posted by anon View Post
    Seems it uses both JS and CSS attacks, there's more info here:
    What the Internet knows about you
    I though so, without being entirely sure.

    On one of my browser, I don't use noscript, but have only SafeHistory & SafeCache installed, and the site could not see any fragment of my history.



    I like very much this question in the FAQ:

    Q: I am a very popular conservative politician. Also, I do like visiting adult websites. Should I be concerned?
    Reply With QuoteReply With Quote
    Thanks

  7. #6
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,439
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39439
    On one of my browser, I don't use noscript, but have only SafeHistory & SafeCache installed, and the site could not see any fragment of my history.
    I just did the JavaScript-based test and it could find five of my visited sites, even though I have disabled history in Opera...

    Edit: happens on both v10 and v9.64.

    Edit 2: after adding the code shoulder posted on his CSS leak tutorial to my Opera custom style sheet and forcing all pages to use it, I get:
    Congratulations, we did not find anything in this category in your browser history.
    Feel free to try our other browser history tests.
    I remember Zorvak mentioned a "randomstring" attack I should still be vulnerable to, though.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •