Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I just tested it on both iPhone and Android and it does indeed remove itself from history and replaces with a link to a weather domain. That’s incredible that it is allowed and I can trivially think of a way to get someone to get to a fake banking site right now, or for that matter, fill the history with a series of visits to domestic violence sites or even worse!


https://developer.mozilla.org/en-US/docs/Web/API/Location/re...

This is known and commonly used -- since 1996. What's the risk? You can't change records about other domains.


I knew about history.replace but I had no idea you could cross sites. Suppose a site, for example, leaves a trail of Amazon Shopping, and curious, you go to it to recall what you did, but it’s Amaz0n instead.


Well there's no need to suppose. While I think if it hasn't been exploited in 30 years, there probably isn't an attack surface, you can always demonstrate and report an exploit.


I dont think its highly exploitable, but you could get people in trouble - have them visit innocuous website during a vulnerable time window, spray a bunch of adult websites into their history, report them to the boss, future visits do not inject history items.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: