Categories: All

Here’s How This Web Page Sniffs Anyone’s Browser History Using Sniffly Attack

SP’s: By abusing the HTTP policies of your web browser, a security engineer has devised a new technique to sniff the browsing history. Using Sniffly and HSTS timing attack, an arbitrary website can violate the privacy of its users. Read ahead to more about how it’s done in detail.

In this article, I’m going to tell you about Sniffly. It’s an attack that abuses the HTTP Strict Transport Security and Content Security Policy to allow a website to sniff a user’s past browser history.
Today tracking the web users is something that website owners do very often using malware injection, cookies, enforcing paywalls and malicious ad scripts. Well, there’s a new technique using the browser fingerprinting is in town. In a demonstration at ToorCon 2015, Yan Zhu, a privacy engineer, showed how to do this and the working of Sniffly attack.

To showcase the demo, Yan has made a web page http://zyan.scripts.mit.edu/sniffly/. You can visit it in Firefox/Chrome/Opera with HTTPS everywhere and see how Sniffly digs your browsing history in the left column.

Here’s how Sniffly works:
When you visit the Sniffly page, your web browser tries to load the images from various HSTS domains over HTTP. Sniffly sets a CSP policy that restricts images to HTTP, so that image sources are redirected to HTTPS.

When an image is blocked by CSP, the time taken for the image to be redirected from HTTP to HTTPS is calculated. If the time is of the order of a millisecond, it means no network request was made and it was HSTS redirect. This implies that the user had earlier visited this domain.

However, if the time the taken to redirect the request is of the order of 100 milliseconds, it means the user hasn’t visited the domain before as a network request probably occurred.

The Sniffly attack is allowed if you visit a site that supports HSTS, it can sniff your browsing history by measuring the redirect time.

To know more about the Sniffly attack, visit the Yan’s GitHub page.
spatsariya

Share
Published by
spatsariya

Recent Posts

How To View Your Instagram Reel History: 4 Ways

Quick Answer Instagram does not keep a history of the Reels you watch. The app…

3 hours ago

Can you Scale with Kanban? In-depth Review

What works well for one team becomes chaos when scaled to a department or company…

3 days ago

Type Soul Trello V2 Link (2025)

Inspired by the super-popular anime and manga series Bleach, Type Soul is a Roblox game…

4 days ago

Zerith H1: The First Humanoid Robot for Hotel Housekeeping

The hospitality sector is embracing a tech revolution with the introduction of the Zerith H1…

5 days ago

Asus Vivobook S14 OLED Review: A Real MacBook Alternative

The Vivobook S14 OLED delivers impressive value by combining a sleek, lightweight design with the…

5 days ago

How To Make Marriage in Infinite Craft?

Infinite Craft is a fun sandbox game that challenges players to create new items by combining…

6 days ago