Collected research
Abusing HTTP Status Codes to Expose Private Information
A hidden image whose src is a GMail profile photo fires onload when the visitor is signed in and onerror when the request redirects instead, revealing login state silently. The same trick works with script tags against Twitter, Facebook and Digg because those URLs return 200 or 403/404 depending on session state. Google called it expected behaviour.
Record
- Researcher
- Mike Cardwell
- Published by
- grepular.com
- Date
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mike Cardwell, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .