Web Hack List

Collected research

Latex Gloves: Protecting Browser Extensions from Probing and Revelation Attacks

Browser extensions give themselves away: a page can probe web-accessible resources by URL, and an extension that injects a WAR reference into the page reveals Firefox per-profile random UUID. Combining revelation with probing uniquely identifies about 90 percent of content-injecting extensions and yields a stable per-browser tracking identifier.

Record

Researcher
Alexander Sjösten, Steven Van Acker, Pablo Picazo-Sanchez and Andrei Sabelfeld
Published by
ndss-symposium.org
Format
Whitepaper
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Alexander Sjösten, Steven Van Acker, Pablo Picazo-Sanchez and Andrei Sabelfeld, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .