2018-07-16 00:05:33 +02:00
|
|
|
<!DOCTYPE html>
|
|
|
|
<html>
|
|
|
|
<head>
|
2019-09-04 00:30:20 +02:00
|
|
|
<title>Data-URL Test</title>
|
|
|
|
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
|
|
|
|
<link href="testIcon.svg" type="image/png" rel="icon">
|
|
|
|
<link href="testIcon.svg" type="image/png" rel="shortcut icon">
|
2020-11-21 13:58:32 +01:00
|
|
|
<link rel="stylesheet" href="../default.css" type="text/css">
|
2018-07-16 00:05:33 +02:00
|
|
|
<style>
|
2018-07-21 00:17:00 +02:00
|
|
|
iframe, object, embed {
|
2018-07-16 00:05:33 +02:00
|
|
|
display: block;
|
|
|
|
box-sizing: border-box;
|
|
|
|
width: 100%;
|
|
|
|
height: 7em;
|
|
|
|
}
|
2020-11-21 13:58:32 +01:00
|
|
|
#code {
|
|
|
|
font-size: 70%;
|
|
|
|
}
|
2018-07-16 00:05:33 +02:00
|
|
|
</style>
|
2018-07-21 00:17:00 +02:00
|
|
|
<link rel="stylesheet" href="data:text/css;base64,Ym9keXtiYWNrZ3JvdW5kLWNvbG9yOiNlMGZmZTA7fQ==">
|
2018-07-16 00:05:33 +02:00
|
|
|
</head>
|
|
|
|
<body>
|
2019-09-04 00:30:20 +02:00
|
|
|
<h1>Data-URL test</h1>
|
|
|
|
This test might not work properly if any other addon is installed that changes the CSP headers (e.g. NoScript or uBlock Origin).
|
|
|
|
<h2>Expected result</h2>
|
|
|
|
<ul>
|
|
|
|
<li>the "Normal" and "blob" iFrames show faked hashes</li>
|
|
|
|
<li>the "Data-URL" iFrame, object and embed shows nothing</li>
|
|
|
|
<li>the whole page has a green background</li>
|
|
|
|
</ul>
|
|
|
|
<h2>Tests</h2>
|
|
|
|
<h3>Normal iFrame</h3>
|
2018-07-16 00:05:33 +02:00
|
|
|
<iframe src="sendFingerprintTest.html"></iframe>
|
2019-09-04 00:30:20 +02:00
|
|
|
<h3>Data-URL iFrame</h3>
|
2019-04-10 01:04:40 +02:00
|
|
|
<iframe id="iframe" src="data:text/html;base64,<?php
|
2018-07-21 00:17:00 +02:00
|
|
|
echo base64_encode(
|
|
|
|
str_replace(
|
|
|
|
'const origin = "iframe";',
|
|
|
|
'const origin = "data URL iframe";',
|
|
|
|
file_get_contents("sendFingerprintTest.html")
|
|
|
|
)
|
|
|
|
);
|
|
|
|
?>"></iframe>
|
2019-09-04 00:30:20 +02:00
|
|
|
<h3>blob iFrame</h3>
|
2018-07-21 13:20:45 +02:00
|
|
|
<iframe id="blobIframe"></iframe>
|
2019-09-04 00:30:20 +02:00
|
|
|
<h3>Data-URL object</h3>
|
2018-07-21 00:17:00 +02:00
|
|
|
<object
|
2018-08-28 21:09:03 +02:00
|
|
|
type="text/html"
|
2019-04-10 01:04:40 +02:00
|
|
|
data="data:text/html;base64,<?php
|
2018-07-21 00:17:00 +02:00
|
|
|
echo base64_encode(
|
|
|
|
str_replace(
|
|
|
|
'const origin = "iframe";',
|
|
|
|
'const origin = "data URL object";',
|
|
|
|
file_get_contents("sendFingerprintTest.html")
|
|
|
|
)
|
|
|
|
);
|
|
|
|
?>"
|
|
|
|
></object>
|
2019-09-04 00:30:20 +02:00
|
|
|
<h3>Data-URL embed</h3>
|
2018-07-21 00:17:00 +02:00
|
|
|
<embed
|
2018-08-28 21:09:03 +02:00
|
|
|
type="text/html"
|
2019-04-10 01:04:40 +02:00
|
|
|
src="data:text/html;base64,<?php
|
2018-07-21 00:17:00 +02:00
|
|
|
echo base64_encode(
|
|
|
|
str_replace(
|
|
|
|
'const origin = "iframe";',
|
|
|
|
'const origin = "data URL embed";',
|
|
|
|
file_get_contents("sendFingerprintTest.html")
|
|
|
|
)
|
|
|
|
);
|
|
|
|
?>"
|
|
|
|
></embed>
|
2019-09-04 00:30:20 +02:00
|
|
|
<h3>iFrame code</h3>
|
2018-07-16 00:05:33 +02:00
|
|
|
<pre id="code"></pre>
|
|
|
|
<script src="dataUrlTest.js"></script>
|
2018-07-21 00:17:00 +02:00
|
|
|
|
|
|
|
<div id="log"></div>
|
2022-05-04 13:30:47 +02:00
|
|
|
<form id="form" method="POST" action="https://bounce.kkapsner.de/requestDetails.php"">
|
2018-07-21 00:17:00 +02:00
|
|
|
<input name="internalId" value="id to be used to link the requests">
|
|
|
|
<textarea style="display: block;" name="fingerprint"></textarea>
|
|
|
|
<button>submit</button>
|
|
|
|
</form>
|
|
|
|
<script>
|
|
|
|
function draw(canvas){
|
|
|
|
"use strict";
|
|
|
|
|
|
|
|
canvas.setAttribute("width", 220);
|
|
|
|
canvas.setAttribute("height", 30);
|
|
|
|
|
2019-12-16 19:27:28 +01:00
|
|
|
const fp_text = "BrowserLeaks,com <canvas> 10";
|
2018-07-21 00:17:00 +02:00
|
|
|
|
2019-12-16 19:27:28 +01:00
|
|
|
const ctx = canvas.getContext("2d");
|
2018-07-21 00:17:00 +02:00
|
|
|
ctx.textBaseline = "top";
|
|
|
|
ctx.font = "14px 'Arial'";
|
|
|
|
ctx.textBaseline = "alphabetic";
|
|
|
|
ctx.fillStyle = "#f60";
|
|
|
|
ctx.fillRect(125, 1, 62, 20);
|
|
|
|
ctx.fillStyle = "#069";
|
|
|
|
ctx.fillText(fp_text, 2, 15);
|
|
|
|
ctx.fillStyle = "rgba(102, 204, 0, 07)";
|
|
|
|
ctx.fillText(fp_text, 4, 17);
|
|
|
|
|
|
|
|
return ctx;
|
|
|
|
}
|
|
|
|
function topTest(){
|
|
|
|
"use strict";
|
|
|
|
|
|
|
|
// create window canvas
|
2019-12-16 19:27:28 +01:00
|
|
|
const canvas = document.createElement("canvas");
|
2018-07-21 00:17:00 +02:00
|
|
|
// draw image in window canvas
|
2019-12-16 19:27:28 +01:00
|
|
|
const ctx = draw(canvas);
|
2018-07-21 00:17:00 +02:00
|
|
|
return {
|
|
|
|
imageData: ctx.getImageData(0, 0, canvas.width, canvas.height),
|
|
|
|
url: canvas.toDataURL(),
|
|
|
|
isPointInPath: getIsPointInPath(ctx)
|
|
|
|
};
|
|
|
|
}
|
|
|
|
function getIsPointInPath(ctx){
|
|
|
|
"use strict";
|
2019-11-30 02:05:37 +01:00
|
|
|
|
2018-07-21 00:17:00 +02:00
|
|
|
ctx.beginPath();
|
|
|
|
ctx.moveTo(20, 19);
|
|
|
|
ctx.lineTo(40, 19);
|
|
|
|
ctx.lineTo(30, 30);
|
|
|
|
ctx.closePath();
|
|
|
|
ctx.stroke();
|
|
|
|
|
|
|
|
return ctx.isPointInPath(30, 19);
|
2019-11-30 02:05:37 +01:00
|
|
|
}
|
2018-07-21 00:17:00 +02:00
|
|
|
function hashToString(hash){
|
2019-11-30 02:05:37 +01:00
|
|
|
"use strict";
|
|
|
|
|
2019-12-16 19:27:28 +01:00
|
|
|
const chunks = [];
|
2018-07-21 00:17:00 +02:00
|
|
|
(new Uint32Array(hash)).forEach(function(num){
|
|
|
|
chunks.push(num.toString(16));
|
|
|
|
});
|
|
|
|
return chunks.map(function(chunk){
|
|
|
|
return "0".repeat(8 - chunk.length) + chunk;
|
|
|
|
}).join("");
|
|
|
|
}
|
2019-11-30 02:05:37 +01:00
|
|
|
|
2019-12-16 19:27:28 +01:00
|
|
|
const send = function(){
|
2019-11-30 02:05:37 +01:00
|
|
|
"use strict";
|
2019-12-16 19:27:28 +01:00
|
|
|
return async function send(form, {url, imageData, isPointInPath}){
|
|
|
|
const buffer = new TextEncoder("utf-8").encode(url);
|
|
|
|
const hashes = await Promise.all([
|
2019-11-30 02:05:37 +01:00
|
|
|
crypto.subtle.digest("SHA-256", buffer),
|
|
|
|
crypto.subtle.digest("SHA-256", imageData.data)
|
2019-12-16 19:27:28 +01:00
|
|
|
]);
|
|
|
|
const data = JSON.stringify({
|
|
|
|
urlHash: hashToString(hashes[0]),
|
|
|
|
imageDataHash: hashToString(hashes[1]),
|
|
|
|
isPointInPath
|
|
|
|
}, null, "\t");
|
|
|
|
form.fingerprint.value = data;
|
|
|
|
const xhr = new XMLHttpRequest();
|
|
|
|
xhr.open("POST", form.action + "?main", true);
|
|
|
|
xhr.onreadystatechange = function(){
|
|
|
|
if (this.readyState === 4){
|
|
|
|
const status = this.status;
|
|
|
|
if (status === 200 || status === 304) {
|
|
|
|
console.log("Sending xhr successful from main page:", data);
|
2018-07-21 00:17:00 +02:00
|
|
|
}
|
2019-12-16 19:27:28 +01:00
|
|
|
else {
|
|
|
|
console.log("Sending xhr failed:", this);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
};
|
|
|
|
xhr.send(new FormData(form));
|
2019-11-30 02:05:37 +01:00
|
|
|
};
|
|
|
|
}();
|
2018-07-21 00:17:00 +02:00
|
|
|
|
|
|
|
send(document.getElementById("form"), topTest());
|
|
|
|
</script>
|
2018-07-16 00:05:33 +02:00
|
|
|
</body></html>
|