Torrent Invites - Get your free bittorrent tracker invitations! - Powered by vBulletin
Ad
Page 5 of 18 FirstFirst ... 234567815 ... LastLast
Results 41 to 50 of 171
Like Tree38Likes

Thread: Security Warning (CSS Hack)

  1. #41

    Posts
    3,086
    I just completed additional tests using IE, Chrome, Safari, Opera, HistoryBlock and NoScript. HistoryBlock users need to be especially careful how they surf:


    UPDATES [October 10th]

    UPDATE 1 - HistoryBlock & NoScript Add-ons
    • NoScript only works with Java based exploits
    • HistoryBlock does not work if you browse both sites at the same time*
    *HistoryBlock utilizes the tab closed & download complete addEventListeners to initiate a history wipe. That leaves you exposed if you have both sites open in separate tabs at the same time or open TI from the same tab without going to an intermediate page first. Also be aware that HistoryBlock will erase cookies upon tab closure.

    UPDATE 2 - Disabling Browser History
    • Does not work in IE
    • Does not work in Opera
    • Does not work in Safari
    *Disabling history only works properly in Firefox.



  2. To remove ads become VIP. Inquire about advertising here.
  3. #42

    Posts
    336

    I want to second Jumbaleo, ethicks and vegas.
    Just want to make clear for everyone:

    to disable visited css, edit
    <mozilla firefox folder>\greprefs\all.js

    Change--> pref("layout.css.visited_links_enabled", false);

    As I see this will disable the css hack, and it does not have too much effect on the font/text apperance.

    I would still suggest to remove TI from history in any means, since in the future there could be any new exploit to gather the history data.
    My big THANKS to: Pascualito, goover, konVILEeuted, smtsh, Knievel and The-Deh

  4. #43

    Posts
    312
    inserting
    Code:
    pref("layout.css.visited_links_enabled", false);
    into user.js is even better because neither firefox nor its addons can change that. user.js has the highest priority.
    if there is no user.js just create it.

  5. #44

    Posts
    30
    What should I do under Opera ?

  6. #45

    Posts
    88
    From what i read if you are using Opera 9.02+ you are safe

  7. #46

    Posts
    112
    Neither of the tests found anything for me so I'm fairly confident, I'm secure.

  8. #47

    Posts
    495
    I'm not too sure that this is a CSS script.

    I'm thinking it's more of a HTML_REFERRER code that they put in. Any site can see it. If you have a website that has cPanel, check the website logs. It will show all of the visitors IPs and some other information, including the website you were just on. That's why most sites use Anonymity.com or anonym.to for external links - Dave, you should consider that.

    Be safe!
    -Tom

  9. #48

    Posts
    162
    tomz, I will happily show you a snippet of CSS code which will reveal whether you have been to some URLs in a given list or not. That is why this is a security warning - it cannot reveal your browsing history but it sure can be used to discriminate between users of a particular site, and there is no way to "block" or "patch" it as such, due to the nature of CSS.

    Your point about the HTTP referrer header is a valid one, but well known. Most people wouldn't be clicking links from T-I directly to a tracker homepage anyway, even if links weren't directed through anonym.to, and [good] browsers can be set to not send referrer headers anyway.
    Last edited by adb; 10-13-2009 at 06:25 PM.
    http://bit.ly/69agFa

    Member (mostly PU or greater) of: BG; BHDTV; BMTV; BitMe; BTN; CE; Demonoid; FTS; Fux0r; GFT; IPT; MVids; PS; PiN; PTM; PtN; PTP; RevTT; SCC; ST; STC; STM; TB; TC; TL; TVT; W.FM; W.CD

  10. #49

    Posts
    495
    I've never really experimented with CSS before, or even JS for that matter, so I have no clue when it comes to that sort of stuff, but the HTTP_REFERRER can't be blocked unless you get an addon, or use a good browser. Having an anonymous.com or anonym.to plugin on this forum wouldn't be a bad idea either.

    -Tom

  11. #50

    Posts
    2,041
    we do have an anon redirect.

Page 5 of 18 FirstFirst ... 234567815 ... LastLast

LinkBacks (?)

  1. 06-27-2010, 12:59 AM
  2. 05-07-2010, 03:09 AM
  3. 04-30-2010, 02:57 AM
  4. 03-22-2010, 12:13 PM
  5. 03-03-2010, 11:33 PM
  6. 02-01-2010, 06:11 AM
  7. 01-16-2010, 02:13 PM
  8. 01-16-2010, 12:20 PM
  9. 12-08-2009, 07:57 PM
  10. 12-06-2009, 09:16 AM
  11. 12-04-2009, 07:33 PM
  12. 10-29-2009, 03:14 PM
  13. 10-26-2009, 06:51 AM
  14. 10-24-2009, 07:59 PM
  15. 10-14-2009, 12:41 PM
  16. 10-12-2009, 09:55 AM
  17. 10-12-2009, 09:46 AM
  18. 10-09-2009, 08:23 PM
  19. 10-09-2009, 04:13 PM
  20. 10-09-2009, 01:20 PM
  21. 10-09-2009, 02:14 AM
  22. 10-08-2009, 06:15 PM

Similar Threads

  1. CSS Hack
    By Ching_Fu in forum Help
    Replies: 5
    Last Post: 10-26-2011, 09:23 PM
  2. Replies: 0
    Last Post: 05-01-2011, 08:18 AM
  3. [Approved] CSS Hack publicity
    By Cpomer in forum Suggestions
    Replies: 15
    Last Post: 01-18-2011, 04:26 PM
  4. CSS Hack info test
    By Canadian in forum BitTorrent Discussion
    Replies: 5
    Last Post: 01-11-2011, 12:07 AM
  5. CSS Hack precaution procedures
    By the0ne in forum Suggestions
    Replies: 1
    Last Post: 10-19-2009, 09:16 PM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •