Web Hack List

Collected research

Cross Domain Leakage With Image Size

ha.ckers.org web application security lab - Archive » Cross Domain Leakage With Image Size

A remotely hosted image whose dimensions vary with the viewer's login state leaks cross-domain user state, since the embedding page can read the rendered size. Extends the same trick to fingerprinting servers via PHP easter eggs and Apache default icons, and to presence detection when the image 404s. Framed as CSRF-based state disclosure.

Record

Document
ha.ckers.org web application security lab - Archive » Cross Domain Leakage With Image Size
Published by
ha.ckers.org
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .