Web Hack List

Later archive addition

CSP fingerprinting with same-origin redirects

The article shows that Firefox's handling of same-origin redirects under Content Security Policy leaks whether a target URL redirects. By embedding carefully chosen resources and observing policy outcomes, an attacker can fingerprint authenticated application state and other redirect-dependent information across origins.

Record

Researcher
やっていく気持ち and @lmt_swallow

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of やっていく気持ち and @lmt_swallow, first published at the original source. Preserved copies are kept so the citation survives its host.