SPI Labs has discovered a practical method of using JavaScript to detect the search queries a user has entered into arbitrary search engines. All the code needed to steal a user's search queries is written in JavaScript and uses Cascading Style Sheets (CSS). This code could be embedded into any website either by the website owner or by a malicious third party through a Cross-site Scripting (XSS) attack. There it would harvest information about every visitor to that site. . . Innovative Security Team uncovers a technique utilizing Python to hijack user browsing histories via CSRF exploitation.. JavaScript Attacks, Cross Site Scripting, Data Harvesting Techniques, Web Security Analysis, Security Threats. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.