Stealing Data with CSS: Attack and Defense
mike-gualtieri.com
mike-gualtieri.com
http://mksben.l0.cm/2015/10/css-based-attack-abusing-unicode...
if it's via xss, i'm not sure what the advantage of this is compared to a javascript payload, other than you being able to get those tinfoil hat folks running noscript.
For ex. if you have a proper CSP with `default-src 'none'` you should be fine so long as you didn't allow `*` or `unsafe-inline` in any of the other `<X>-src` directives.
[1]. G. Heyes, D. Lindsay, and E.V. Nava, “The Sexy Assassin: Tactical Exploitation Using CSS” (2009), http://slideplayer.com/slide/3493669/
[2] [CSSconf.eu 2013] Mike West - XSS. (No, the _other_ "S"), https://youtu.be/eb3suf4REyI?t=582
[3] https://twitter.com/blubbfiction/status/657632031845826560
[4] Demo PoC http://eaea.sirdarckcat.net/cssar/v2/