Web Hack List

Top 10 winner

Cross-domain leaks of site logins via Authenticated CSS

Security: Cross-domain leaks of site logins

Detects whether a visitor is logged in to a third-party site by loading that site's stylesheet with <link> and reading a property back with getComputedStyle. MySpace serves margin-bottom:3px to logged-in users and 0px otherwise. Argues any non-randomised CSS property value is readable cross-origin, including data: URIs in background-url.

Record

Document
Security: Cross-domain leaks of site logins
Researcher
Chris Evans
Published by
scarybeastsecurity.blogspot.com
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .