CEO of Bit Discovery, Professional Hacker, Black Belt in Brazilian Jiu-Jitsu, Off-Road Race Car Driver, Founder of WhiteHat Security, and Maui resident.
Thursday, March 01, 2007
I still know where you've been, without JavaScript
Looks like RSnake has one-upped me with his new CSS History Hack Without JavaScript (PoC). The hack still relies up the a:visited component of CSS, but instead of using JavaScript to check link color, he uses the display: property to create the conditional logic required. Nice! This is mitigated in many ways by SafeHistory (Firefox), but again, your not protected by turning off JavaScript. Great. In classic pdp fashion, he quickly improved upon the PoC with his own version. Good stuff.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment