shineva
小狐狸
小狐狸
  • UID36831
  • 注册日期2011-07-26
  • 最后登录2013-12-16
  • 发帖数30
  • 经验10枚
  • 威望0点
  • 贡献值0点
  • 好评度1点
阅读:3411回复:8

扩展ShowIP会泄露用户的浏览历史

楼主#
更多 发布于:2012-05-02 03:04
A Firefox add-on that gives users the ability to collect information on the IP address, server hostname and other related data for websites they visit also has the added bonus feature of reporting the same information on every site visited to a third-party server, SophosLabs reports. The ShowIP add-on exposes the full Web-browsing history of its users to the add-on's back-end service—and anyone who can intercept the unencrypted packets.

Sophos' Graham Cluely writes that he was alerted to the problem by a reader, who found a recent update to the ShowIP add-on sends the full URL of sites visited in unencrypted form—including those visited using HTTP Secure and in "private browsing" mode—to a Web server at api.ip2info.org, without alerting the user. The behavior is a potential privacy threat to users of the service, because the data leaked by the add-on could be used by anyone sharing the network they are on to reconstruct their Internet browsing history.

The issue has been reported on the add-on's Google Code project page, but there has been no response.

大体是说这个扩展会把用户所有浏览过的网址以未加密的形式上传到第三方服务器上.

原文地址
http://arstechnica.com/business/news/20 ... mments-bar
游客

返回顶部