Hack: Site steals your browsing history based on URL link color
caughtyouwatching.com
caughtyouwatching.com
<a class="digg" href="http://digg.com/submit/">...digg button code...</a>
Now you can use CSS to hide visited links. a.digg:visited { display: none; }http://www.w3.org/TR/CSS21/selector.html#link-pseudo-classes
Note. It is possible for style sheet authors to abuse the :link and :visited pseudo-classes to determine which sites a user has visited without the user's consent.
UAs may therefore treat all links as unvisited links, or implement other measures to preserve the user's privacy while rendering visited and unvisited links differently. See [P3P] for more information about handling privacy.
Exposing browsing history via CSS color information in the DOM is a serious security hope that should be closed by browser vendors.
Demonstrates how powerful the technique is.
It's one of those things which has questionable ethics…but honestly? A little awesome...
http://antirez.com/page/cachetest.html
AFAIK the bug I shown is not currently fixed. The idea is to perform a request for an image in the target site (usually the logo), meter how many milliseconds it takes, if it takes very little (near to zero) you already visited the site. If the latency is instead in the normal range you didn't. See the article for more info.
... why would I be down-voted for mentioning a solution which prevents 100% of JavaScript history attacks???
At one time browsers didn't display images by default eiter. It was horrible.
Sure, goodsite.com can choose to spy on you... but that is less likely than some other random site being the bad one.
Ah, but you won't know if your history's being stolen, right? The exploit can be hidden from the user's eyes, hidden in an ad, for example, that the site you trust shows you without realizing that ad is hacking your history. Phishing sites, too, of course.
A big problem caused by this elegant hack is that it uses services web users can't easily do without, services that most browser users don't know about (and, ideally, shouldn't need to understand). I guess you're suggesting that a user must be more wary of websites, avoiding unknown ones. Is that what you're suggesting?
It'll be interesting to see what can be tried to remedy the privacy issues caused by this.