Hacker Uses XSS and Google Street View Data to Determine Physical Location
securityweek.com
securityweek.com
http://www.schneier.com/essay-187.html
There were similar privacy concerns when it was found that Microsoft were able to generate unique identifying fingerprints of PC's, which they used for license tracking.
This just proves that the debate then was moot since MAC addresses would become universal unique identifiers. Now everything from phones, routers, computers and laptops all have unique IDs.
To make the situation worse and unlike the Intel debate, the growth of WiFi means that these unique ID's are actually being broadcast for anybody to pick up and read.
RFID will only make this situation worse. There was so much of a fuss about the Intel ID's back in 99 that I can only think that people care less about their privacy today.
Set geo.enabled to false.
Not clear how to do the equivalent in Chrome yet. What's alarming is, in my brief search, there does not seem to be an easy way to retroactively go back and delete permissions formerly/accidentally granted.
Same thing with html5 storage (offtopic but related). There is likewise no way I know of to browse what exactly is stored in html5 storage via the browser (preferences or otherwise).
As much as I love my own real (not internet) privacy, I don't depend on people not knowing where I am. The success of sites such as Foursquare lead me to believe a large amount of people feel the same way.
SSL helps mitigate the damage to some extent, but only if the site uses SSL.
EDIT: I was referring to the original article, schneier has a point, if the users has the default password set then yes he can login, but how is that even possible on most browsers today which prevents you from sending ajax request to anything but the original server?
EDIT2: Just tried it and got a error from chrome: 400 Bad Request Cross Site Action detected!
edit: Here's more info...
The hack relies on a specific XSS vulnerability in the Verizon FiOS router. It requires that you're already logged into your router or that you're using default username/password.
That said, I've upvoted you for the link.
He's using an XSS vulnerability in the router admin interface to execute JavaScript on the router's pages, so he can use JavaScript to do pretty much anything the user can do.
But even without an XSS exploit you can make cross-domain POSTs using forms, and GETs using IMG or SCRIPT tags. You just can't get the response, so it's not suitable for this attack where you need to get the MAC address out.
The "Drive-by Pharming" mentioned in the link I posted used the latter technique, because all it needs to do is POST some form that tells the router to update the DNS settings, it doesn't need the response.
He actually mentioned that technique in the video, but sort of glossed over it (right before "now, this isn't necessary in our geolocation XXXSS attack")
Maybe, even if the user changed the default password, he probably stored the new credentials in the browser.
If this allow to know here you are not (eg: you're not at home), this can be useful to a couple of people.
a+'.'+b+'.'+c+'.'+d
where a=192 b=168 c=0-255 b=0-255
Of course this could be any private network address range[1]. Next you would use document.write or .innertext to make these iframes. Personally I wouldn't stop at the first one. I would log all the frames that loaded into an array and from there test them further. I would also get the users IP address and tack on :80, :8080, :21, ect and see what I am presented with- web torrent frontends, ftp servers, ect.
for(var c=0;i<255;i++) { for (var d=0;j<255;j++) { document.write('<iframe height="1" width="1" src="http://192.168. + c + '.' + d + '" id="' + i + '.' + j + '" name="' + c + '.' + d + '"></iframe>'); } }
<iframe> portscans, wow.
For a massively-deployed hack like Samy's, it makes plenty of sense to just check the small handful of major-brand wifi routers.