pith. sign in

arxiv: 1211.4812 · v1 · pith:VEGPZLNCnew · submitted 2012-11-20 · 💻 cs.CR

XSS-FP: Browser Fingerprinting using HTML Parser Quirks

classification 💻 cs.CR
keywords browserexactfingerprintingdeterminehtmlparserquirkstype
0
0 comments X
read the original abstract

There are many scenarios in which inferring the type of a client browser is desirable, for instance to fight against session stealing. This is known as browser fingerprinting. This paper presents and evaluates a novel fingerprinting technique to determine the exact nature (browser type and version, eg Firefox 15) of a web-browser, exploiting HTML parser quirks exercised through XSS. Our experiments show that the exact version of a web browser can be determined with 71% of accuracy, and that only 6 tests are sufficient to quickly determine the exact family a web browser belongs to.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.