Collected research
Cross Domain Leakage With Image Size
ha.ckers.org web application security lab - Archive » Cross Domain Leakage With Image Size
A remotely hosted image whose dimensions vary with the viewer's login state leaks cross-domain user state, since the embedding page can read the rendered size. Extends the same trick to fingerprinting servers via PHP easter eggs and Apache default icons, and to presence detection when the image 404s. Framed as CSRF-based state disclosure.
Record
- Document
- ha.ckers.org web application security lab - Archive » Cross Domain Leakage With Image Size
- Published by
- ha.ckers.org
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .