Web Hack List

Collected research

Abusing HTTP Status Codes to Expose Private Information

A hidden image whose src is a GMail profile photo fires onload when the visitor is signed in and onerror when the request redirects instead, revealing login state silently. The same trick works with script tags against Twitter, Facebook and Digg because those URLs return 200 or 403/404 depending on session state. Google called it expected behaviour.

Record

Researcher
Mike Cardwell
Published by
grepular.com
Date
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mike Cardwell, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .