Any protection against browser history snooping via CSS?

Bug reports and enhancement requests
Post Reply
bslade
Posts: 1
Joined: Tue May 25, 2010 7:48 pm

Any protection against browser history snooping via CSS?

Post by bslade »

According to the article Feasibility and Real-World Implications of Web Browser History Detection at http://w2spconf.com/2010/papers/p26.pdf , the authors were able to snoop the browser history via CSS style sheets for 74% of the users who accessed their test websites.

Any chance NoScript might someday protect against this?

Ben
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Any protection against browser history snooping via CSS?

Post by therube »

Alternative views: http://docs.google.com/viewer?a=v&q=cac ... LoEr_z99DQ

Isn't Mozilla doing something about browser history snooping ;-).

Plugging the CSS History Leak

A New Type of Phishing Attack
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.9) Gecko/20100317 SeaMonkey/2.0.4
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3370
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

Re: Any protection against browser history snooping via CSS?

Post by GµårÐïåñ »

I'm pretty sure this was previously discussed and NoScript indeed does protect against it. You might also take a look at Giorgio's blog, its on there as well IIRC.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
Post Reply