Closed
Bug 601527
Opened 14 years ago
Closed 14 years ago
CSS Exploit allows for Privacy Invasion
Categories
(Firefox :: Security, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 147777
People
(Reporter: trappmanrhett, Unassigned)
References
()
Details
(Keywords: privacy)
Attachments
(1 file)
2.41 KB,
application/x-javascript
|
Details |
User-Agent: Mozilla/5.0 (Windows NT 6.0; rv:2.0b6) Gecko/20100101 Firefox/4.0b6
Build Identifier: Mozilla/5.0 (Windows NT 6.0; rv:2.0b6) Gecko/20100101 Firefox/4.0b6
Please see attached "proof of concept".
Reproducible: Always
Keywords: privacy
What version of Firefox did you test this on?
Do you have a URL where the whole thing is hosted, or do I have to incorporate that JavaScript snippet into a site in order to test?
This should have been fixed in 4.0 by bug 147777.
Comment 5•14 years ago
|
||
A working copy of Jeremiah Grossman's code is hosted on ha.ckers.org
http://ha.ckers.org/weird/CSS-history-hack.html
The same technique is used for this gender test
http://www.mikeonads.com/2008/07/13/using-your-browser-url-history-estimate-gender/
Neither example "works" in Firefox 4 due to the fix for bug 147777. Compare the results with Firefox 3.6 or any other browser.
Group: core-security
Status: UNCONFIRMED → RESOLVED
Closed: 14 years ago
Resolution: --- → DUPLICATE
You need to log in
before you can comment on or make changes to this bug.
Description
•