Page MenuHomePhabricator
Paste P7886

http leak examples (https://github.com/cure53/HTTPLeaks/blob/master/leak.html)
ActivePublic

Authored by sbassett on Dec 4 2018, 11:53 PM.
<html id="1">
<head>
<base id="2">
<meta id="3"></meta>
<meta id="4"></meta>
<meta id="5"></meta>
<meta id="6"></meta>
<meta id="7"></meta>
<meta id="8"></meta>
<meta id="9"></meta>
<meta id="10"></meta>
<meta id="11"></meta>
<meta id="12"></meta>
<meta id="13"></meta>
<meta id="14"></meta>
<meta id="15"></meta>
<meta id="16"></meta>
<meta id="17"></meta>
<meta id="18"></meta>
<link id="19" />
<link id="20" />
<link id="21" />
<link id="22" />
<link id="23" />
<link id="24" />
<link id="25"></link>
<link id="26" />
<link id="27" />
<link id="28" />
<link id="29" />
<link id="30" />
<link id="31" />
<link id="32" />
<link id="33" />
<link id="34" />
<link id="35" />
<link id="36" />
<link id="37"></link>
<link id="38" />
<link id="39"></link>
<link id="40"></link>
<link id="41"></link>
<link id="42" />
<link id="43" />
<link id="44" />
<link id="45"></link>
<link id="46" />
<link id="47"></link>
<link id="48" />
<link id="49" />
<link id="50" />
<link id="51" />
<link id="52" />
<link id="53" />
<link id="54" />
<link id="55" />
<link id="56" />
<link id="57" />
<link id="58" />
<link id="59"></link>
<link id="60" />
<link id="61" />
<link id="62"></link>
<link id="63" />
<link id="64" />
<link id="65"></link>
<link id="66" />
<link id="67" />
<link id="68" />
<link id="69" />
<link id="70" />
<link id="71"></link>
<link id="72" />
<link id="73" />
</base></head>
<body id="74">
<a id="75">You have to click me</a>
<img id="76"></img>
<map id="77">
</map>
<table id="78">
<tr>
<td id="79"></td>
</tr>
</table>
<img id="80"></img>
<img id="81"></img>
<img id="82"></img>
<img id="83"></img>
<image id="84">
<image id="85">
<svg id="86">
<image id="87">
<image id="88">
</image></image></svg>
<picture>
<source id="89"></source>
</picture>
<picture>
<img id="90"></img>
</picture>
<img id="91"></img>
<img id="92"></img>
</image></image><form id="93"></form>
<form id="test"></form><button id="94"><image id="84"><image id="85">CLICKME</image></image></button>
<form id="test2"></form>
<video id="95"><image id="84"><image id="85"><input id="96"><isindex id="97">
<track id="98"></track>
</isindex></input></image></image></video>
<video id="99"><image id="84"><image id="85"><input id="96"><isindex id="97">
<source id="100"></source>
</isindex></input></image></image></video>
<audio id="101"></audio>
<audio id="102"><image id="84"><image id="85"><input id="96"><isindex id="97">
<source id="103"></source>
</isindex></input></image></image></audio>
<video id="104"></video>
<object id="105"></object>
<object id="106"></object>
<object id="107"></object>
<object id="108">
</object>
<object id="109"></object>
<embed id="110"></embed>
<embed id="111"></embed>
<object id="112">
</object>
<object id="113">
</object>
<script id="114"></script>
<script id="115"></script>
<script id="116"></script>
<script></script>
<iframe id="117"></iframe>
<iframe id="118"></iframe>
<iframe id="119"></iframe>
<iframe id="120"></iframe>
<iframe id="121"></iframe>
<iframe id="122"></iframe>
<iframe id="123"></iframe>
<p id="124"><image id="84"><image id="85"><input id="96"><isindex id="97">Right Click</isindex></input></image></image></p>
<menu id="125">
<menuitem id="126"></menuitem>
</menu>
<style><image id="84"><image id="85"><input id="96"><isindex id="97">
/*# sourceMappingURL=https://leaking.via/css-source-map */
</isindex></input></image></image></style>
<style><image id="84"><image id="85"><input id="96"><isindex id="97">
@import 'https://leaking.via/css-import-string';
@import url(https://leaking.via/css-import-url);
</isindex></input></image></image></style>
<style><image id="84"><image id="85"><input id="96"><isindex id="97">
a:after {content: url(https://leaking.via/css-after-content)}
a::after {content: url(https://leaking.via/css-after-content-2)}
a:before {content: url(https://leaking.via/css-before-content)}
a::before {content: url(https://leaking.via/css-before-content-2)}
</isindex></input></image></image></style><image id="84"><image id="85"><input id="96"><isindex id="97">
<a id="127">ABC</a>
</isindex></input></image></image><style><image id="84"><image id="85"><input id="96"><isindex id="97">
big {
list-style: url(https://leaking.via/css-list-style);
list-style-image: url(https://leaking.via/css-list-style-image);
background: url(https://leaking.via/css-background);
background-image: url(https://leaking.via/css-background-image);
border-image: url(https://leaking.via/css-border-image);
-moz-border-image: url(https://leaking.via/css--moz-border-image-alias);
-webkit-border-image: url(https://leaking.via/css--webkit-border-image-alias);
border-image-source: url(https://leaking.via/css-border-image-source);
shape-outside: url(https://leaking.via/css-shape-outside);
cursor: url(https://leaking.via/css-cursor), auto;
}
</isindex></input></image></image></style><image id="84"><image id="85"><input id="96"><isindex id="97">
<big>DEF</big>
</isindex></input></image></image><style><image id="84"><image id="85"><input id="96"><isindex id="97">
/* Basic font-face */
@font-face {
font-family: leak;
src: url(https://leaking.via/css-font-face-src);
}
/*
* Cross-browser font-face
* IE6-8 will use the EOT source, modern browsers will use WOFF(2) and fallback to TTF in case of error
* More info:
* http://www.paulirish.com/2009/bulletproof-font-face-implementation-syntax/
* http://caniuse.com/#search=eot
* http://caniuse.com/#search=woff2
* http://caniuse.com/#search=woff
* http://caniuse.com/#search=ttf
*/
@font-face {
font-family: 'leak';
src: url('https://leaking.via/css-font-face-src-eot') format('eot'), url('https://leaking.via/css-font-face-src-woff') format('woff'), url('https://leaking.via/css-font-face-src-ttf') format('truetype');
}
big {
font-family: leak;
}
</isindex></input></image></image></style><image id="84"><image id="85"><input id="96"><isindex id="97">
<big>GHI</big>
<svg>
</svg></isindex></input></image></image><style><image id="84"><image id="85"><input id="96"><isindex id="97"><svg>
circle {
fill: url(https://leaking.via/svg-css-fill#foo);
mask: url(https://leaking.via/svg-css-mask#foo);
-webkit-mask: url(https://leaking.via/svg-css--webkit-mask#foo);
filter: url(https://leaking.via/svg-css-filter#foo);
clip-path: url(https://leaking.via/svg-css-clip-path#foo);
}
</svg></isindex></input></image></image></style><image id="84"><image id="85"><input id="96"><isindex id="97"><svg>
</svg>
<s id="128">JKL</s>
</isindex></input></image></image><style><image id="84"><image id="85"><input id="96"><isindex id="97">
s {
--leak: url(https://leaking.via/css-variables);
}
s {
background: var(--leak);
}
s::after {
content: attr(foo url);
}
s::before {
content: attr(notpresent, url(https://leaking.via/css-attr-fallback));
}
</isindex></input></image></image></style>
<style><image id="84"><image id="85"><input id="96"><isindex id="97">
p#p1 {
background-image: \75 \72 \6C (https://leaking.via/css-escape-url-1);
}
p#p2 {
background-image: \000075\000072\00006C(https://leaking.via/css-escape-url-2);
}
</isindex></input></image></image></style>
<p id="p1"><image id="84"><image id="85"><input id="96"><isindex id="97">bla</isindex></input></image></image></p>
<p id="p2"><image id="84"><image id="85"><input id="96"><isindex id="97">bla</isindex></input></image></image></p><image id="84"><image id="85"><input id="96"><isindex id="97">
<b id="129">MNO</b>
<svg>
</svg>
</isindex></input></image></image><div id="130"></div>
<div id="131"></div>
<div id="132"></div>
<div id="133"></div>
<div id="134"></div>
<div id="135"></div><image id="84"><image id="85"><input id="96"><isindex id="97">
<svg id="136">
<defs>
<lineargradient id="Gradient">
</lineargradient>
<mask id="Mask">
</mask>
</defs>
</svg>
<svg id="137">
<image id="138">
</image>
</svg>
<svg id="139">
<image id="140">
</image>
</svg>
<svg id="141">
</svg>
<svg id="142">
<a id="143"><text id="144">CLICKME</text></a>
</svg>
<svg id="145">
</svg>
<svg>
</svg>
</isindex></input></image></image><div id="146"></div>
<script id="147"></script><image id="84"><image id="85"><input id="96"><isindex id="97">
<xml>
</xml>
<line id="148">
</line>
<vmlframe id="149">
</vmlframe>
<line id="150">
</line>
<math id="151">CLICKME</math>
<math><mi id="152">CLICKME</mi></math>
</isindex></input></image></image></body>
</html>

Event Timeline

sbassett changed the title of this paste from https://github.com/cure53/HTTPLeaks/blob/master/leak.html cleaned to http leak examples (https://github.com/cure53/HTTPLeaks/blob/master/leak.html).Sep 27 2019, 5:21 PM