|
|
|
|
|
by kecks
3800 days ago
|
|
This can leak the user's client by changing links per client. Make a link per identifiable client, show only the one for the current client, and give each link a post/get parameter identifying the client. Quite easy to do, but a lot of work to have broad client support. Tada! I now know you read your email on your [obscure and bugged client], which is susceptible to [this and that exploit]. |
|