Categories: All

Here’s How This Web Page Sniffs Anyone’s Browser History Using Sniffly Attack

SP’s: By abusing the HTTP policies of your web browser, a security engineer has devised a new technique to sniff the browsing history. Using Sniffly and HSTS timing attack, an arbitrary website can violate the privacy of its users. Read ahead to more about how it’s done in detail.

In this article, I’m going to tell you about Sniffly. It’s an attack that abuses the HTTP Strict Transport Security and Content Security Policy to allow a website to sniff a user’s past browser history.
Today tracking the web users is something that website owners do very often using malware injection, cookies, enforcing paywalls and malicious ad scripts. Well, there’s a new technique using the browser fingerprinting is in town. In a demonstration at ToorCon 2015, Yan Zhu, a privacy engineer, showed how to do this and the working of Sniffly attack.

To showcase the demo, Yan has made a web page http://zyan.scripts.mit.edu/sniffly/. You can visit it in Firefox/Chrome/Opera with HTTPS everywhere and see how Sniffly digs your browsing history in the left column.

Here’s how Sniffly works:
When you visit the Sniffly page, your web browser tries to load the images from various HSTS domains over HTTP. Sniffly sets a CSP policy that restricts images to HTTP, so that image sources are redirected to HTTPS.

When an image is blocked by CSP, the time taken for the image to be redirected from HTTP to HTTPS is calculated. If the time is of the order of a millisecond, it means no network request was made and it was HSTS redirect. This implies that the user had earlier visited this domain.

However, if the time the taken to redirect the request is of the order of 100 milliseconds, it means the user hasn’t visited the domain before as a network request probably occurred.

The Sniffly attack is allowed if you visit a site that supports HSTS, it can sniff your browsing history by measuring the redirect time.

To know more about the Sniffly attack, visit the Yan’s GitHub page.
spatsariya

Recent Posts

Apple Upgrades AirTag With Longer Range, Louder Alerts, and No Price Increase

In a world where Apple exists, losing your personal items should only be considered as…

7 hours ago

Amazon Layoff Plans Intensify as Tech Giant Braces for Another Round of Job Cuts

Amazon is famous for its quick package deliveries, yet the company, during this week, demonstrates…

7 hours ago

CoreWeave Stock Jumps as Nvidia Invests $2B in AI Infrastructure Expansion

CoreWeave’s stock increased by 12%, as Nvidia announced its investment of $2 billion in the…

11 hours ago

Intel and AMD Stock Slide as Market Rotates Toward AI and Small-Cap Momentum

The stock market in Monday’s session had some really dramatic twists, which showed some types…

11 hours ago

How Alphabet Stock Could Benefit From AI Monetization Beyond Ads

Alphabet drives the internet’s most effective money generating operation. During the third quarter of 2025,…

14 hours ago