Hackers hide credit card stealing scripts in favicon EXIF data

Started by rcjordan, June 25, 2020, 11:55:15 PM

Previous topic - Next topic

rcjordan


gm66

Civilisation is a race between disaster and education ...

ergophobe

Another reason to run an image-optimization script that strips EXIF data I guess.

rcjordan


ergophobe

Of course they can. I probably would not have thought of it in a million years, but the second someone says it...

rcjordan

"Powerful tracking vector

The attack works against Chrome, Safari, Edge, and until recently Brave, which developed an effective countermeasure after receiving a private report from the researchers. Firefox would also be susceptible to the technique, but a bug prevents the attack from working at the moment."

New browser-tracking hack works even when you flush caches or go incognito | Ars Technica
https://arstechnica.com/information-technology/2021/02/new-browser-tracking-hack-works-even-when-you-flush-caches-or-go-incognito/