+ Reply to Thread
Page 11 of 15 FirstFirst ... 910111213 ... LastLast
Results 151 to 165 of 223

Thread: CSS History Leak and how to prevent it even with enabled history [Firefox & Opera]

  1. #151

    Join Date
    10.04.10
    Location
    Transilvania
    P2P Client
    uTorrent
    Posts
    126
    Activity Longevity
    0/20 17/20
    Today Posts
    0/5 ssssss126
    Oh, well, that's perfect. Because NoScript is giving me hard time using the site.
    Reply With QuoteReply With Quote
    Thanks

  2. #152
    SBi or what.cd??
    You did allow sbi didn't you
    Reply With QuoteReply With Quote
    Thanks

  3. #153

    Join Date
    10.04.10
    Location
    Transilvania
    P2P Client
    uTorrent
    Posts
    126
    Activity Longevity
    0/20 17/20
    Today Posts
    0/5 ssssss126
    Quote Originally Posted by SBfreak View Post
    SBi or what.cd??
    You did allow sbi didn't you
    Yeah, I allow almost everything except trackers. But most of the trackers are gazelle oriented so there's the problem :) I can't even look at the peerlist. xD
    Reply With QuoteReply With Quote
    Thanks

  4. #154

    Join Date
    12.11.08
    Location
    Europe
    P2P Client
    Nothing ATM
    Posts
    303
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 ssssss303
    I decided to turn history off and only use Speed Dial addon for FF.
    Reply With QuoteReply With Quote
    Thanks

  5. #155
    Moderator
    Instab's Avatar
    Join Date
    17.09.09
    Posts
    6,661
    Activity Longevity
    5/20 17/20
    Today Posts
    0/5 sssss6661
    looks like they finally fixed it MFSA 2010-46: Cross-domain data theft using CSS
    Your account has been disabled.
    Reply With QuoteReply With Quote
    Thanks

  6. Who Said Thanks:

    anonftw (25.07.10) , Vuze-Sbi (24.07.10)

  7. #156
    Advanced User Blocker's Avatar
    Join Date
    11.03.09
    Location
    The Pirate Bay
    P2P Client
    VEM
    Posts
    1,621
    Activity Longevity
    6/20 18/20
    Today Posts
    0/5 sssss1621
    Quote Originally Posted by Instab View Post
    looks like they finally fixed it MFSA 2010-46: Cross-domain data theft using CSS
    So does this firefox add-on will prevent CSS History Leak?

    Description

    Description

    Google security researcher Chris Evans reported that data can be read across domains by injecting bogus CSS selectors into a target site and then retrieving the data using JavaScript APIs. If an attacker can inject opening and closing portions of a CSS selector into points A and B of a target page, then the region between the two injection points becomes readable to JavaScript through, for example, the getComputedStyle() API.
    Last edited by Blocker; 24.07.10 at 18:01.
    Reply With QuoteReply With Quote
    Thanks

  8. #157
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,451
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39451
    Did you actually click on the link?
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  9. #158
    Advanced User Blocker's Avatar
    Join Date
    11.03.09
    Location
    The Pirate Bay
    P2P Client
    VEM
    Posts
    1,621
    Activity Longevity
    6/20 18/20
    Today Posts
    0/5 sssss1621
    Yap sorry ,it's a security announce not an add-on
    Last edited by Blocker; 24.07.10 at 18:18.
    Reply With QuoteReply With Quote
    Thanks

  10. #159

    Join Date
    03.01.08
    Location
    Bavaria
    P2P Client
    Vuze, uSerenity
    Posts
    64
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssssss64
    Damn, guess I should have read this thread, before visiting what.cd in Firefox with SB-I still open...

    Feel a little tension crawling up my spine, if my account will be disabled in a few ...seconds, days, weeks (?).

    I'll keep you updated.
    Reply With QuoteReply With Quote
    Thanks

  11. #160
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,451
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39451
    In the meantime it'd be a good idea to shield yourself up.

    Remember only setting layout.css.visited_links_enabled to false can protect you against the randomstring attack:
    http://ha.ckers.org/weird/CSS-history.cgi
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  12. #161
    For firefox i started

    Stanford SafeHistory

    Stanford SafeCache

    after i became a member of this site...

    I'm sure most of you must have known about the plugins...Very handy tool to have when you are in the cheating business...
    Reply With QuoteReply With Quote
    Thanks

  13. Who Said Thanks:

    Instab (05.08.10)

  14. #162
    Moderator
    Instab's Avatar
    Join Date
    17.09.09
    Posts
    6,661
    Activity Longevity
    5/20 17/20
    Today Posts
    0/5 sssss6661
    Quote Originally Posted by Resurrection View Post
    For firefox i started

    Stanford SafeHistory

    Stanford SafeCache

    after i became a member of this site...

    I'm sure most of you must have known about the plugins...Very handy tool to have when you are in the cheating business...
    yes, both are great but be sure to do the steps from our guide anyway
    Your account has been disabled.
    Reply With QuoteReply With Quote
    Thanks

  15. #163
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,451
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39451
    Quote Originally Posted by Resurrection View Post
    Does this one protect you against the leak test I posted above you?
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  16. #164
    Haha...it told me a bunch of websites I've NOT visited and there is a blank in The following sites were visited: so I suppose I can log on to TL from here...

    But I think the test is 2006 old...

    Maybe codes have improved since...

    I'd like to test these add-ons on a more modern script...
    Reply With QuoteReply With Quote
    Thanks

  17. #165
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,451
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39451
    TL isn't using the CSS leak.

    The test may be somewhat old, but NoScript and the anti-leak stylesheet still don't seem to prevent it from reading your history, so...
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread
Page 11 of 15 FirstFirst ... 910111213 ... LastLast

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •