Mozilla spills the beans on surfer's browsing habits

'I know what you did last session...'

NEWS Netscape and other web browsers based on the Mozilla development project contain a bug that leaks users' web surfing data, according to a new report. The bug reveals the URL of the page a user is viewing to the web server of the site visited last. This allows a web server to track where users go after they leave the site, even if the next web address comes from a bookmark or is manually typed into the browser. Researcher Sven Neuhaus, who published a security alert on Wednesday about the issue to the Bugtraq mailing list, said he had confirmed the bug in Mozilla 1.0, 1.0.1 and 1.1, though it probably also exists in older Mozilla versions. It also appears in browsers based on Mozilla's technology, including Netscape 7 and Galeon, a Linux application, he said. Mozilla is an open-source project initiated by Netscape Communications, now part of AOL Time Warner, to foster volunteer interest in its browser technology. Mozilla's features and its Gecko rendering engine are now used in the Netscape 7 commercial software from AOL Time Warner. The problem lies with a component called "onunload," Neuhaus said. He created a demonstration exploiting the bug, which he said is several weeks old, hoping to prompt Mozilla developers to deliver a fix. In the meantime, Neuhaus said the vulnerability can be worked around by switching off Javascript. Matthew Broersma writes for ZDNet.co.uk

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters