Collected research
Firefox cross-domain information theft (simple text strings, some CSV)
CESA-2008-011
Firefox's window.onerror reports JavaScript error text, and some messages quote the content that failed to parse. Sourcing a remote non-script resource and reading 'blah is not defined' steals one word cross-domain; iterating recovers a whole CSV row. Firefox 3.0.4's generic-message defence falls to the 302 redirect trick. CVE-2008-5507.
Record
- Document
- CESA-2008-011
- Researcher
- Chris Evans
- Published by
- scary.beasts.org
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .