<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>CSS History Probing, or: "I know where you went last week"</title><link>http://blogs.msdn.com/b/ieinternals/archive/2009/06/17/csshistoryprobing.aspx</link><description>Background One of the interesting attacks which makes the rounds every few years concerns the ability of web pages to use CSS to detect whether or not certain URLs have been visited. Given a sufficiently large set of URLs to probe, a website may be able</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: CSS History Probing, or: "I know where you went last week"</title><link>http://blogs.msdn.com/b/ieinternals/archive/2009/06/17/csshistoryprobing.aspx#10128332</link><pubDate>Fri, 11 Feb 2011 23:10:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10128332</guid><dc:creator>EricLaw [ex-MSFT]</dc:creator><description>&lt;p&gt;IE9 Release Candidate has adopted CSS styling restrictions, interoperable with the protections introduced by other latest-version browsers. &lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/b/ieinternals/archive/2011/02/11/ie9-release-candidate-minor-changes-list.aspx"&gt;blogs.msdn.com/.../ie9-release-candidate-minor-changes-list.aspx&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10128332" width="1" height="1"&gt;</description></item><item><title>re: CSS History Probing, or: "I know where you went last week"</title><link>http://blogs.msdn.com/b/ieinternals/archive/2009/06/17/csshistoryprobing.aspx#9988278</link><pubDate>Wed, 31 Mar 2010 18:00:31 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9988278</guid><dc:creator>EricLaw [ex-MSFT]</dc:creator><description>&lt;p&gt;A future version of Firefox is taking a swipe at this problem by disabling all styling of :visited other than color.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blog.mozilla.com/security/2010/03/31/plugging-the-css-history-leak/"&gt;http://blog.mozilla.com/security/2010/03/31/plugging-the-css-history-leak/&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9988278" width="1" height="1"&gt;</description></item><item><title>re: CSS History Probing, or: "I know where you went last week"</title><link>http://blogs.msdn.com/b/ieinternals/archive/2009/06/17/csshistoryprobing.aspx#9948789</link><pubDate>Fri, 15 Jan 2010 04:21:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9948789</guid><dc:creator>EricLaw [ex-MSFT]</dc:creator><description>&lt;p&gt;Pretty cool test page for this probing: &lt;a rel="nofollow" target="_new" href="http://www.whattheinternetknowsaboutyou.com/top20k"&gt;http://www.whattheinternetknowsaboutyou.com/top20k&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9948789" width="1" height="1"&gt;</description></item><item><title>re: CSS History Probing, or: "I know where you went last week"</title><link>http://blogs.msdn.com/b/ieinternals/archive/2009/06/17/csshistoryprobing.aspx#9799626</link><pubDate>Tue, 23 Jun 2009 18:32:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9799626</guid><dc:creator>EricLaw [ex-MSFT]</dc:creator><description>&lt;p&gt;@Stephen: Sure, you could try to trade performance for privacy, but obviously you still would have to block JavaScript, which isn't workable for many major sites that users care about. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Even with pure CSS, however, it would probably still be possible to execute the attack unless the user is willing wait forever for pages to load, because the CSS could be made to take nearly forever to run.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9799626" width="1" height="1"&gt;</description></item><item><title>re: CSS History Probing, or: "I know where you went last week"</title><link>http://blogs.msdn.com/b/ieinternals/archive/2009/06/17/csshistoryprobing.aspx#9799574</link><pubDate>Tue, 23 Jun 2009 18:12:33 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9799574</guid><dc:creator>Stephen Baker</dc:creator><description>&lt;p&gt;Interesting security flaw. &amp;nbsp;Of course there's another solution. &amp;nbsp;If the browser didn't try to be as smart, and just prefetched all urls referred to in the css then the attacker wouldn't know if they had actually visited the site or not.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9799574" width="1" height="1"&gt;</description></item></channel></rss>