Page 1 of 3 123 LastLast
Results 1 to 10 of 28

Thread: New css attack

  1. #1
    Tv Controls you's Avatar Resistance is Futile BT Rep: +2
    Join Date
    Nov 2009
    Location
    Land of Hypocrisy
    Posts
    1,266


    It uses the fact that properties within display: when combined with a:visited creates conditional logic. That condition will not fire certain things within the block. In this case I am including a nonexitant background image background: url(...); set in the CSS itself that is seemless to the user. The image actually points to a CGI script with the information about the URL that has been visited and is then logged along with the IP address of the user for later retrieval.
    I took the picture with no-script and anti-css leak script running at the same time.
    Pretty scary that this can make it past all this extra security.

    Mozilla definitely needs to address this soon, as it is starting to get out of hand if you ask me....

    *I can confirm however that private browsing does negate this new attack... But it's still sort of a pain to browse like that.
    Last edited by Tv Controls you; 07-06-2010 at 10:49 PM.

  2. BitTorrent   -   #2
    Using a separate browser for What.cd trackers sites that may attempt to read your history keeps on being the best choice.

    Quote Originally Posted by Tv Controls you View Post
    *I can confirm however that private browsing does negate this new attack... But it's still sort of a pain to browse like that.
    What about disabling history entirely?
    Last edited by anon; 07-06-2010 at 10:49 PM. Reason: Automerged Doublepost
    "I just remembered something that happened a long time ago."

  3. BitTorrent   -   #3
    Tv Controls you's Avatar Resistance is Futile BT Rep: +2
    Join Date
    Nov 2009
    Location
    Land of Hypocrisy
    Posts
    1,266
    What about disabling history entirely?
    I have not tried it yet....

    here is the link to the test site. (the one I tested with, in the picture I uploaded)

    http://ha.ckers.org/weird/CSS-history.cgi
    Last edited by Tv Controls you; 07-06-2010 at 10:51 PM.

  4. BitTorrent   -   #4
    Quote Originally Posted by Tv Controls you View Post
    It's the same in Opera. Even with history and JavaScript disabled and the anti-leak stylesheet.
    "I just remembered something that happened a long time ago."

  5. BitTorrent   -   #5
    Slickerey's Avatar <3 FST BT Rep: +2
    Join Date
    Dec 2009
    Posts
    482
    For some weird reason, it's not working with me.

    I don't have the anti-leak script, NoScript, or anything else.

  6. BitTorrent   -   #6
    Quote Originally Posted by Slickerey View Post
    For some weird reason, it's not working with me.

    I don't have the anti-leak script, NoScript, or anything else.
    History disabled or private browsing maybe?
    "I just remembered something that happened a long time ago."

  7. BitTorrent   -   #7
    Slickerey's Avatar <3 FST BT Rep: +2
    Join Date
    Dec 2009
    Posts
    482
    I'm not using private browsing, but I am using custom settings for history.

  8. BitTorrent   -   #8
    tesco's Avatar woowoo
    Join Date
    Aug 2003
    Location
    Canadia
    Posts
    21,664
    Quote Originally Posted by Tv Controls you View Post
    Mozilla definitely needs to address this soon, as it is starting to get out of hand if you ask me....
    Well all browser makers are going to have to come up with something, and that probably means the w3c coming up with a new css spec for a:visited that disables background-urls that aren't inherited from a:link.

  9. BitTorrent   -   #9
    Tv Controls you's Avatar Resistance is Futile BT Rep: +2
    Join Date
    Nov 2009
    Location
    Land of Hypocrisy
    Posts
    1,266
    Quote Originally Posted by tesco View Post
    Quote Originally Posted by Tv Controls you View Post
    Mozilla definitely needs to address this soon, as it is starting to get out of hand if you ask me....
    I'm missing how this is mozilla specific.
    It will have the same effect in every browser that supports css a:visited.
    Yes, I know but Mozilla is the only one who will address this within the next year

    IE will allow this to go on for ages, as they most likely don't care at all.

  10. BitTorrent   -   #10
    Slickerey's Avatar <3 FST BT Rep: +2
    Join Date
    Dec 2009
    Posts
    482
    Here are my settings in case anybody wishes to try them out...


    Let us (FST) know if it works for you so we can spread the word.
    Last edited by Slickerey; 07-06-2010 at 11:07 PM.

Page 1 of 3 123 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •