Skip to content

bnadarevic/HistoryTrack

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

11 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

HistoryTrack

This demo is tricking user into discovering browsing history to attacker(in this case subreddits).

Visited and nonvisited links look differently(visited links are by default purple while nonvisited are blue). It used to be possible to abuse this with getComputedStyle to spy on user's browsing history [1] [2].

In 2010 browser vendors fixed it so getComputedStyle returns same value regardless of whether link is visited or not [3]. However site can still control properties of visited links, this demo contains links to popular(safe for work) subreddits disguised as a clicking game. User is instructed to click only on green circles and press button when he's done. Circles that represent links to subreddits that user already visited will be displayed as green while the ones he did not visit are displayed as orange.

screenshot

About

CSS history leak disguised as a clicking game

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 2

  •  
  •