Other nomination
Cross Domain Leakage With Image Size
A remotely hosted image whose dimensions vary with the viewer's login state leaks cross-domain user state, since the embedding page can read the rendered size. Extends the same trick to fingerprinting servers via PHP easter eggs and Apache default icons, and to presence detection when the image 404s. Framed as CSRF-based state disclosure.
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.