+ Reply to Thread
Results 1 to 6 of 6

Thread: YouPorn, Perez Hilton Exploit Bug to Obtain Your Browsing History

  1. #1
    Advanced User ParamouR's Avatar
    Join Date
    01.09.10
    Location
    Third Rome
    P2P Client
    µ
    Posts
    773
    Activity Longevity
    0/20 16/20
    Today Posts
    0/5 ssssss773

    YouPorn, Perez Hilton Exploit Bug to Obtain Your Browsing History



    Researchers at the University of California San Diego have discovered a bug that many sites are using to track the browsing behavior of their visitors. The flaw was found on some 485 websites, including YouPorn, Perez Hilton and Wired, and reportedly reveals all of the other sites that each user has previously visited. Of the 485 sites affected by the bug, 63 were found to be copying the data, while 46 were "hijacking" user information, usually to target ads, or find out which rival sites users had visited.

    The bug extracts browsing information via a color-changing mechanism that many browsers use to mark sites that you've already visited. A script on YouPorn, for example, would exploit the privacy leak to check which other links to porn sites have already been changed to purple (meaning that you've already clicked on them). "Our study shows that popular Web 2.0 applications like mashups, aggregators, and sophisticated ad targeting are rife with different kinds of privacy-violating flows," the researchers wrote [PDF].

    Forbes's Kashmir Hill investigated the sites mentioned in the paper, and discovered that some, including YouPorn and PixMac, had created the code themselves. Others, meanwhile, seemed to obtain it from third-party developers. Hill's trail ultimately led to three advertising networks, including one called Interclick. "Interclick purchases anonymous audience data from several vendors for the purpose of targeting advertising campaigns," the company said in a statement provided to Forbes. "Consequently, it has a number of quality control measures in place to understand the quality and effectiveness of this data. The code observed in the paper was a quality measure being tested."

    A spokesman for Morningstar, a finance site cited in the paper, insists that the company was unaware that Interclick had gathered user information via the script. In that particular case, the code automatically scanned a visitor's browsing history for any car sites he or she had previously visited. Interclick, however, says that the test was unsuccessful, and that it stopped running the script in October.
    Researchers insist, though, that their findings underscore a "pressing need to devise flexible, precise and efficient defenses" against such history-hijacking practices. Fortunately, not all browsers are vulnerable to the bug. Chrome and Safari, for example, automatically guard against it, as does the latest version of Firefox. Internet Explorer, on the other hand, is still susceptible, but users can protect themselves by activating a feature called InPrivate Browsing.
    Source : Switched
    Last edited by ParamouR; 05.12.10 at 23:16.
    Show respect to all people, but grovel to none​


    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    Mihai (11.12.10)

  3. #2
    Member supermarrioh's Avatar
    Join Date
    06.01.08
    Location
    secretsbipornocellar
    P2P Client
    secretsbipornocellar
    Posts
    590
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss590
    Öhm, What.cd and some others did this, too....
    "I like waffles."
    "Pardon, you like what?"
    Reply With QuoteReply With Quote
    Thanks

  4. #3
    Guest Coder
    Owyn's Avatar
    Join Date
    08.05.10
    Location
    Russia
    P2P Client
    uSerenity
    Posts
    478
    Activity Longevity
    0/20 17/20
    Today Posts
    0/5 ssssss478
    lol, it's 100% your fault to be using "Internet explorer"
    信心正気宇裁
    Reply With QuoteReply With Quote
    Thanks

  5. #4
    Member supermarrioh's Avatar
    Join Date
    06.01.08
    Location
    secretsbipornocellar
    P2P Client
    secretsbipornocellar
    Posts
    590
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss590
    Possible with Firefox, too. Theres a thread around here in which counter measures are described.
    "I like waffles."
    "Pardon, you like what?"
    Reply With QuoteReply With Quote
    Thanks

  6. #5
    Advanced User ParamouR's Avatar
    Join Date
    01.09.10
    Location
    Third Rome
    P2P Client
    µ
    Posts
    773
    Activity Longevity
    0/20 16/20
    Today Posts
    0/5 ssssss773
    Quote Originally Posted by supermarrioh View Post
    Possible with Firefox, too. Theres a thread around here in which counter measures are described.
    Yeah Fire-Fox also is vulnerable but its more safer as compared to other Browsers.
    Show respect to all people, but grovel to none​


    Reply With QuoteReply With Quote
    Thanks

  7. #6
    some trackers use it too...

    just bloack the css hack
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •