4 ms·
Why would anyone think favicons are worth writing a pseudo-security article about.
by soheil 2y ago
Why would anyone think favicons are worth writing a pseudo-security article about.
- 1970-01-01 2y agoIt's not the icon, it's the hash value. If it doesn't match a known hash, you have an imposter. Full stop.
- praash 2y agoNo - the point is to quickly detect random websites that simply duplicate known favicons! Matching hashes can only occur in these cases: - the site is a careless impostor - the site is the real deal - a hash collision
- 1970-01-01 2y agoWe agree here. The point is to detect imposters via favicon. Case 1 is easy, simple, and a legitimate concern. Case 2 is the inverse of case 1. A host is misconfigured or something. Much harder to detect, but no more important. Case 3 should not exist.
- toast0 2y ago> Case 3 should not exist. Case 3 must exist by the pigeonhole principle given that the hashes are smaller than most favicons. Otoh, if it does show up, you can exclude it by doing a full comparison.
- HeatrayEnjoyer 2y agoIf it does show up you go play the lottery where the odds are far less long.
- likeabatterycar 2y agoIf that was true, we could finally abandon PKI and just use favicons...
- 1970-01-01 2y agoMarry the favicon sha256 hash with a list of hostnames and put the values into trusted database..
- gs17 2y agoThe "practical example" in the article is the exact opposite of that, it searches for the hash of a known favicon and filters to sites that shouldn't match it but do. It would require a particularly incompetent attacker (or a very contrived case) to not match the favicon of a public website.
- nunobrito 2y agoQuite a mediocre article. Suspicious that it got upvoted but the person posting it doesn't seem to have done with malicious intent. So, just a waste of time for anyone hoping to see an exploit based on favicons.
- grajaganDev 2y agoOSINT is not about exploits. Favicons are very useful for spotting phishing sites and finding forgotten servers.
- nunobrito 2y agoIn which planet would that be valid? OSINT is about exploiting public data for private benefit. The article was meh, others are expressing similar opinions if you read. It is OK that you find it useful but for me was sincerely expecting something more from the title.
- kevin_thibedeau 2y agoThis is mostly showing IoT devices that are exposed to the internet.
- maxmorlocke 2y agoWe review the web presence of a business as our core product offering for payment processors, etc. as they look to onboard ecomm merchants. This (and techniques like it) make a great way to find scummy actors and have a proveable piece of evidence as opposed to a 'yea, this looks off' or 'this doesn't fit the profile of what an established business looks like'. We leverage a lot of subtle signals like this.