TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tracking browser behavior without any tools (security breach in most browsers)

6 点作者 urlwolf大约 16 年前

7 条评论

fertqer13412大约 16 年前
This issue is nine years old at this point and has been published, republished, and blogged countless times. I yearn for the day it stops wasting space on the front page of news aggregators.<p>A partial bibliography:<p>2000:<p><a href="http://bugzilla.mozilla.org/show_bug.cgi?id=57351" rel="nofollow">http://bugzilla.mozilla.org/show_bug.cgi?id=57351</a><p>2002:<p><a href="http://seclists.org/bugtraq/2002/Feb/0271.html" rel="nofollow">http://seclists.org/bugtraq/2002/Feb/0271.html</a><p><a href="http://bugzilla.mozilla.org/show_bug.cgi?id=147777" rel="nofollow">http://bugzilla.mozilla.org/show_bug.cgi?id=147777</a><p>2006:<p><a href="http://portal.acm.org/citation.cfm?id=1135777.1135884" rel="nofollow">http://portal.acm.org/citation.cfm?id=1135777.1135884</a><p><a href="http://portal.acm.org/citation.cfm?id=1135777.1135854" rel="nofollow">http://portal.acm.org/citation.cfm?id=1135777.1135854</a><p><a href="http://jeremiahgrossman.blogspot.com/2006/08/i-know-where-youve-been.html" rel="nofollow">http://jeremiahgrossman.blogspot.com/2006/08/i-know-where-yo...</a><p>2008:<p><a href="http://azarask.in/blog/post/socialhistoryjs/" rel="nofollow">http://azarask.in/blog/post/socialhistoryjs/</a><p><a href="http://www.mikeonads.com/2008/07/13/using-your-browser-url-history-estimate-gender/" rel="nofollow">http://www.mikeonads.com/2008/07/13/using-your-browser-url-h...</a>
varenc大约 16 年前
One of the coolest uses I've seen of this vulnerability is to look at the users history to only show them the digg/reddit/HN/technorati/etc share links to websites they use.<p><a href="http://www.azarask.in/blog/post/socialhistoryjs/" rel="nofollow">http://www.azarask.in/blog/post/socialhistoryjs/</a>
ars大约 16 年前
<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=147777" rel="nofollow">https://bugzilla.mozilla.org/show_bug.cgi?id=147777</a>
评论 #580378 未加载
tptacek大约 16 年前
Wow am I ever not OK with browser security demonstrations that crash my browser.<p>From the JS, It looks like this is just this old trick:<p><a href="http://ha.ckers.org/weird/CSS-history-hack.html" rel="nofollow">http://ha.ckers.org/weird/CSS-history-hack.html</a>
arantius大约 16 年前
I was worried for a brief moment, when I saw my personal site (domain: my username + dot com) show up in the list. I thought: that couldn't be in their list of sites to check for via the visited-link-css-pseudoclass trick, could it? It is! And 99,999 other sites:<p><a href="http://startpanic.com/db/db_en.txt" rel="nofollow">http://startpanic.com/db/db_en.txt</a><p>As mentioned, this isn't new.
DenisM大约 16 年前
Cute.<p>So suppose I want to know who my visitors are, but I do not want to resort to underhanded tactis like this. Any ideas on how to get to know my customers yet respect their privacy?
barrkel大约 16 年前
I don't get it. It didn't do <i>anything</i>. It just says this:<p>[img: Ready now?]<p>Correct? You bet [...]
评论 #580457 未加载