More information about the Underscore mailing list

[_] Direct scripting with CSS alone

Richard Davey rich at corephp.co.uk
Wed Sep 5 12:52:33 BST 2007

Hi _,

One of my favourite security bloggers posted this little demo up.

It demonstrates how advanced CSS is getting, including full send and
retrieval of data (with *NO* JavaScript at all), Browser History
recognition and link tracking.

http://www.businessinfo.co.uk/labs/css_scripting_kit/css_scripting_kit.php

This is for FF only at the moment.

It doesn't look like much on the surface, but View Source and check
out the Style block. This is just the tip of the iceberg.

Cheers,

Rich
-- 
Zend Certified Engineer
http://www.corephp.co.uk

"Never trust a computer you can't throw out of a window"