邪恶八进制信息安全团队技术讨论组's Archiver

EvilOctal 2006-3-9 02:44

[转载]Protecting Browser State from Web Privacy Attacks

信息来源:[url]http://crypto.stanford.edu/sameorigin/[/url]

Through a variety of means, including a range of browser cache methods and inspecting the color of a visited hyper- link, client-side browser state can be exploited to track users against their wishes. This tracking is possible because per- sistent, client-side browser state is not properly partitioned on per-site basis in current browsers. We address this prob- lem by reopening the general notion of a "same-origin" policy and implementing two browser extensions that enforce this policy on the browser cache and visited links.

页: [1]
© 1999-2008 EvilOctal Security Team