Not that you can't do that with a anchor, param, or an endpoint that can take arbitrary numbers/strings.
I'd love to know the explanation too.
Not that you can't do that with a anchor, param, or an endpoint that can take arbitrary numbers/strings.
I'd love to know the explanation too.
In an extreme case imagine that someone sends you a password in a messaging app which is available via the web. If an attacker can trick you to open webpages (maybe they intercept a HTTP site and open a few tabs) they can detect if the page scrolled based on side channels (data transfer) or direct information (did you load a lazy-loaded image from their server?). You can use this to learn page content. This is vaguely similar to https://en.wikipedia.org/wiki/CRIME.
As a concrete example imagine that a webpage has something like this past the first page.
<p>Your password is 56acc1bc03298ec0</p>
<img loading=lazy src=https://cdn.example/secure.png>
If I can trick you to load #:~:text=Your password is 5 and observe that you looked up the DNS for cdn.example and loaded secure.png (especially if that resource isn't cachable) I have learned the first character of the password.If I do this 64 times (on average) I have learned the whole password.
This is a little hard to do, especially with pop-up blockers being built into most browsers so it is hard for a site to open many top-level windows (origin isolation of modern browsers will likely block this in iframes) it is not too extreme of a case.
Of course there are simpler attacks. Maybe someone can link to https://www.youtube.com/feed/history#:~:text=Voice+Feminizat... and they can tell if you have watched this video based on how many thumbnails have loaded. You load too many thumbnails and you get thrown in jail for being trans.
1. I think you could potentially embed an iframe on a page and use the scroll positions combined with this feature to read information on a page. Start with "a", check scroll position, then "ab", then "abc". Similar to a blind sql attack where you gather data/hashes by continuously adding to the SELECT query using a substring function and a sleep (to detect if the substring was found). You brute force character by character. I believe this is commonly called an "Oracle attack"
2. XSS/Phishing/Spam. You add a png with a "Your account has been compromised" or a "fake form" (think Google docs) or whatever your spam message is to a part of a page. You send an email with this special url that will cause it to jump directly to that location on load.
Just some theories. I'm pretty sure the first one would qualify for some sort of bounty, but my experience is most bug bounty programs wouldn't count the second one as valid (requires user interaction).