Top 10 winner
Cross-domain leaks of site logins via Authenticated CSS
Security: Cross-domain leaks of site logins
Detects whether a visitor is logged in to a third-party site by loading that site's stylesheet with <link> and reading a property back with getComputedStyle. MySpace serves margin-bottom:3px to logged-in users and 0px otherwise. Argues any non-randomised CSS property value is readable cross-origin, including data: URIs in background-url.
Record
- Document
- Security: Cross-domain leaks of site logins
- Researcher
- Chris Evans
- Published by
- scarybeastsecurity.blogspot.com
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .