Welcome back...


your tracking ID is:






This is a small proof-of-concept for a revived variant of EverCookie based on XHR Preflight Cache Poisoning.

Interesting take aways:

How this POC works :

  1. User visits e.g. https://evercookie.0x41.link/xhrpreflight/.
  2. A JS script generates a number of XHRs in order to set a randomly generated ID in browsers' XHR preflight cache
  3. Another JS script maps out the previously injected ID from the browsers XHR preflight...
  4. ID is displayed to the user (this can be used to set the tracking cookie)
How to mitigate this: Restart your browser and clear entire cache.

All major browsers are affected (04/04/2021)

Author:

Piotr DuszyƄski (@drk1wi) http://duszynski.eu