Visitor History Scanning

cybrax

Community Advocate
Community Support
Messages
764
Reaction score
27
Points
0
Some of you may know about this or not,
in which case then this is going to be interesting reading.

Using a well known weakness inherent in all web browsers a shrewd webmaster could read portions of a visitors recent browsing history and use this information to alter the page content according to the visitor surfing history.

My question is simple, how many of you folk know about this exploit or have ever included it in a site? Did Google have a problem with it being used also springs to mind.. the plan was to use the technique to fine tune adsense by dynamically tweeking the meta tags but any other suggestions of how it could be used are more than welcome.

For those in need of a proof of concept working demo of history scanning we keep a little one on the glevum site :
http://glevum.x10.mx/pages/page_history.php
 

bhupendra2895

New Member
Messages
554
Reaction score
20
Points
0
Thanks, nice trick.It made me think that, if some webmaster stores our IP on database and uses this method to track which popular site we visit and which pages of that site we visit so often, is an attack on our privacy.This information can be exploited for all possible hacking attempts.Similar effect can be achieved by cookies.
Is private mode of internet explorer or any other browser able to prevent this?
 
Last edited:

cybrax

Community Advocate
Community Support
Messages
764
Reaction score
27
Points
0
Not tried with 'Privacy' mode perhaps somebody here will.

From what I understand the exploit is to be plugged sometime this year or next with new browser releases from Safari, Mozilla and Microsoft.
 
Top