Hi everyone! I did this. It was just a random cool idea I wanted to try. It worked a little too well and I quickly moved it to a disposable site to test if the page will get penalised by Google. I got busy with other things and forgot about it. When I bumped into it again I decided to write about it, for two reasons: 1) To me it's hard to believe that Chrome would allow for this to happen in the first place and 2) th…
How I recorded user behaviour on my competitor’s websites
201–210 of 329 posts
Re: How I recorded user behaviour on my competitor’s websites
#202Earlier quoted context omitted.
Thank you Cyrus. I thought it would be obvious that this isn't a practical tactic a reputable brand could risk doing.
While it is clear that you did not have any bad intentions, you should never have published it on the web. Based on your earlier comment "It worked a little too well" it becomes clear that multiple users were tricked by your site and that you possibly even intercepted submitted forms ("I gasped when I realised I can actually capture all form submissions and send them to my own email."). You misled people and breached…
Re: How I recorded user behaviour on my competitor’s websites
#203Am I reading this correctly? He's been doing this since 2013 and still wants to use the white hat card?
Re: How I recorded user behaviour on my competitor’s websites
#204Earlier quoted context omitted.
> Domain names being little endian has been one of the most expensive web sec mistakes in history. Can you clarify what you mean by this?
Presumably that authority works from right-to-left. .com, then domain, then subdomain. It would be easier to gauge trust if it were left-to-right.
Re: How I recorded user behaviour on my competitor’s websites
#205Earlier quoted context omitted.
If you didn't steal anything, what would the charge be?
So anyone can just come walk around inside your house without your permission, and you think it’s legal and no problem as long as they don’t take anything? I could see that being the perspective in another culture but it certainly isn’t how the US works.
Not only that, they can move in!
Here in Belgium a young couple left the country to do volunteering work only to hear from friends back home that gypsies had squatted their house. Official reaction of the mayor of Ghent was "I can't do anything about it ... it's complicated"
Obviously breaking & entering is a crime but if you're "living" there, only the courts can kick you out after following all the necessary legal steps.
UK has (had) similar squatting laws but afaik those were mainly (ab)used in the 90s to throw parties in abandoned warehouses.
Re: How I recorded user behaviour on my competitor’s websites
#206Earlier quoted context omitted.
... Don't use the back button? What? I actually kind of like the ability to move between pages and domains with the back button.
A good website give you the ability to move without this button. It's like Android VS iOS. The first one has a back button, the other don't.
Re: How I recorded user behaviour on my competitor’s websites
#207Earlier quoted context omitted.
I'm curious how many visitors did this. In my very limited sample set of myself and friends / work colleagues, we all use middle click to open a result in a new tab.
The vast majority of regular users I've seen go back and forth between search and search results. Heck, I do it from time to time. Most users are extremely "inefficient" by geek standards.
How is that inefficient? I use both interchangeably and I don't see how it's any less efficient than opening a new tab and then having to close it if it's not what you want, or having to close useless tabs if the first one is all you need... On my Macbook, I just swipe right and I'm back at the search results.
Re: How I recorded user behaviour on my competitor’s websites
#208Earlier quoted context omitted.
It's sad that everyone is being so harsh to you just because you decided to post about a vulnerability that who knows thousands of other people are quietly exploiting for their own benefit. If anything I am happy that instead of trying to misuse it or keeping it a secret you made it public knowledge so that there can be something done about it. Yes you could have handled it more appropriately and you probably will in…
Howdy, former Matasano pentester here. FWIW, I would probably have done something similar to them before I'd worked in the security industry. It's an easy mistake to make, because it's one you make by default: intellectual curiosity doesn't absolve you from legal judgement, and people on the internet tend to flip out if you do something illegal and say anything but "You're right, I was mistaken. I've learned my lesso…
Do you have any idea how patronizing your tone is?
Re: How I recorded user behaviour on my competitor’s websites
#209It’s also a bit rich to see all the outrage here and deranking by google, since hijacking/proxying to sites in search results is exactly what AMP does.
Re: How I recorded user behaviour on my competitor’s websites
#210Earlier quoted context omitted.
The vast majority of regular users I've seen go back and forth between search and search results. Heck, I do it from time to time. Most users are extremely "inefficient" by geek standards.
> Most users are extremely "inefficient" by geek standards. How is that inefficient? I use both interchangeably and I don't see how it's any less efficient than opening a new tab and then having to close it if it's not what you want, or having to close useless tabs if the first one is all you need... On my Macbook, I just swipe right and I'm back at the search results.