Create account

replied 2347d
Tried researching exploits/vulns based on imgs with external sources. Not really finding anything that serious or that hasn't been fixed. Will look into more.
replied 2347d
It doesn't need to be an exploit, preventing broken SSL is enough reason not to do it. Also, external content can be used to track memo users.
replied 2347d
You can't implement a system to block broken SSL requests from rendering images to display? Not to sound anti-privacy, but there are plenty of other ways to track Memo users already.
Simon Van Gelder
replied 2347d
My test vector was spoofing the return header and sending back something that's not an image.