I went to go check the stats for my blog today and noticed an unusual link listed as being monitored. Upon further research it seems that the link is actually a web page from the blog that someone had downloaded onto their desktop. Looking back at some hits to the site, I noticed that this isn't the first time that someone's local location has been disclosed to my stats counter (see Figure).
You can see that the location of the user's desktop is shown (even though there is no use in that), the person's username (and therefore their account) is being exposed. If you have high profile website that many people are pulling web pages from you could essentially put together a user list, which can be used later on for password guessing. This little flaw is a great example of information leakage.

0 comments:
Post a Comment