Collected research
CSS History Stealing Acts As Cookie
ha.ckers.org web application security lab - Archive » CSS History Stealing Acts As Cookie
CSS history stealing repurposed as a persistent cookie substitute. The site forces a visit to a per-user unique URL, then on return iterates candidate URLs to recognise the visitor. Matan Gillon's refinement uses a ten-deep tree of virtual folders to hold 10^10 identities in 100 probes, defeating cookie deletion and shared-proxy IP collapse.
Record
- Document
- ha.ckers.org web application security lab - Archive » CSS History Stealing Acts As Cookie
- Published by
- ha.ckers.org
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .