DEV Community

Discussion on: Stealing Accounts with an IMG Tag

Collapse
 
omicron666 profile image
Omicron

there are informations to add :

  • you won't steal http-only cookies
  • this is principle of 1x1 pixel images for tracking users
  • you can make it look like it is an image, rename your php file to .png, and add proper .htaccess directives on php/apache to execute such file or file extension as php script for example
Collapse
 
nastyox1 profile image
nastyox • Edited

All true! Here is how people can make the URL have a fake file extension. I'd also add to the "more about this" list that people like to use this technique to track whether you've opened their emails or not.

Collapse
 
yoelblum profile image
Yoel

this is principle of 1x1 pixel images for tracking users

I think a normal pixel tracker (like Facebook's) doesn't do this. It only sends it's own (Facebook's) cookies together with the request, so it doesn't need to "steal" any cookies since this is normal browser behavior (not anymore on Safari)