4 ms·
>if somebody sent you an email with that code (even if you never open the email) then you would be the unwitting owner of one share of Krispy Kreme Donuts Pard
by mtempm 9y ago
>if somebody sent you an email with that code (even if you never open the email) then you would be the unwitting owner of one share of Krispy Kreme Donuts
Pardon my ignorance, but how would this work?
- grav 9y agoI felt ignorant first when reading it as well. But looking at the "FAQ" at the bottom, it says: "But this only affects people that are logged in, right? Yes ..." So I suppose what happens is, that the user is already logged into the service and thus has a cookie for the service in his browser. If the user then somehow executes a request to the URL in the article with the same browser (eg viewing a malicous email with the IMG tag in a webmail client), the browser will enclose the cookie in the header of the request. This makes the request automatically authenticated.
- mtempm 9y ago>eg viewing a malicous email with the IMG tag in a webmail client The article mentions it would occur even without opening the email.
- palunon 9y agoWell, it is possible your email client is doing prefetching. I wouldn't rate it as probable, since you're unlikely to have a client with the same cookies than your web browser, but still. You could also abuse Firefox and Chrome prefetching links. I'm not sure Gmail for example remove prefetching attributes in spam links. They do block images though.
- mtempm 9y agoGood point. Anyways, how would it work with the server receiving any data from the client just by viewing the link in your browser?