Forgot your password?
typodupeerror
This discussion has been archived. No new comments can be posted.

Abusing HTTP Status Codes To Expose Private Info

Comments Filter:
  • by toetagger (642315) on Wednesday January 26, 2011 @11:28AM (#35009010)
    I don't know... What if I would do this in my slashdot signature, trying to load a picture only available for people on the RIAA Intranet. Then I could show a different signature to the RIAA than to everyone else. Copy/Paste for FBI, your HR/employer, or even your spouse.
  • Re:Not quite (Score:4, Interesting)

    by ArcherB (796902) on Wednesday January 26, 2011 @11:31AM (#35009052) Journal

    It might not work as well as they think. I got this as I read down a bit:

    First of all. Lets check if you're logged into GMail right now (not including Google Apps)... (Yes, you are logged in).

    Actually, I am browsing with Chrome, but have not opened GMail in this session at all, not once since the reboot. Maybe it is something Chrome is doing, since I get "No, you're not logged in" while using the incognito window.

    If you are using your gmail account to download bookmarks, custom home page or whatever Chrome may be logging into gmail for, it may throw off the result.

    However, in saying that, I noticed that it reported me logged into Facebook, which I am not, nor have I since my last reboot. I'm running Firefox 3.6.13.

Real Users hate Real Programmers.

Working...