Read More:
The next front in the cookie wars: Fighting the Evercookie | IT Security | TechRepublic.com
The next front in the cookie wars: Fighting the Evercookie | IT Security | TechRepublic.com
“Evercookie is a JavaScript API that produces extremely persistent cookies in a browser. Its goal is to identify a client even after they’ve removed standard cookies, Flash cookies, and others.”
Here we go again.
Let’s assume the cookie data we want to store is “bcde”. Evercookie then accesses the following URLs in the background:
These URLs are now stored in the browser’s history. When checking for a cookie, Evercookie loops through all the possible characters on google.com/Evercookie/cache/, starting with “a” and moving up, but only for a single character.
- google.com/evercookie/cache/b
- google.com/evercookie/cache/bc
- google.com/evercookie/cache/bcd
- google.com/evercookie/cache/bcde
- google.com/evercookie/cache/bcde-
Once it sees a URL that was accessed because it’s in the browser’s history, it attempts to brute force the next letter. This process occurs extremely fast because no requests are made to the server in question. Evercookie knows it has reached the end of the string as soon as it finds a URL that ends in “-”.
TechRepublic: Can Evercookie be defeated by disabling JavaScript or using an application like NoScript?
Samy Kamkar: Yes, NoScript or turning off JavaScript will prevent the Evercookie from being created.
My Computer
At a glance
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
- Computer type
- PC/Desktop
- Computer Manufacturer/Model Number
- Dell Hell oh Well
- OS
- Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
- CPU
- Intel Core 2 Duo 2.93GHz
- Memory
- Not much with my ADHD
- Graphics Card(s)
- ATI Radeon HD 4350
- Monitor(s) Displays
- 24" HDTV/Monitor
- Screen Resolution
- Blurry after a Scotch or 2
- Hard Drives
- 1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
- Case
- Don't get on my case...man :D
- Cooling
- I have an Air Conditioner & Diet Pepsi
- Keyboard
- Saitek Cyborg
- Mouse
- 10 yr old MS optical mouse that still works
- Internet Speed
- Never fast enough
- Antivirus
- Various
- Browser
- Various