Stealing History with JavaScript and CSS







Scenarios

An evil site or an XSS compromised site may contain this history checking script to see if you have been to sites that interest them. They will then use a CSRF to attempt to perform some action at that site as you if you are still authenticated via a cookie.

Note: The example only checks for a few sites but it could check quite a number in a very short time or use a communications request to fetch the list of sites or URLs it is interested in checking for.