mlgualtieri / CSS-Exfil-Protection

Official repository for the CSS Exfil Protection browser extensions.
MIT License
155 stars 11 forks source link

Can you add an alert when it detects the technique? #6

Closed jawz101 closed 6 years ago

jawz101 commented 6 years ago

It would be nice to know when it's being used on the web... I guess if it's something that is a detectable thing.

mlgualtieri commented 6 years ago

Already done! When CSS rules are blocked by the extension a red box appears on the extension icon with the number of rules that were blocked. Check out the plugin tester page to see it in action. It should indicate there were 4 rules blocked: https://www.mike-gualtieri.com/css-exfil-vulnerability-tester

jawz101 commented 6 years ago

dang. I totally didn't pay attention to that :P that's awesome

jawz101 commented 6 years ago

Oh.. I'm also the person who submitted that review on AMO you just responded to. If you wanted someone to reach out to on Brave I believe the author of WebAPI Manager now works for them doing privacy research. I've emailed him in the past and he's pretty personable.

mlgualtieri commented 6 years ago

Thanks! I will definitely do that. I'm extremely swamped at the moment with work, but when I get a chance to breathe I'll reach out to him.