Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Black Hat

Hacker Uses XSS and Google Street View Data to Determine Physical Location

Black Hat - How I met your GirlfriendSamy Kamkar, in an incredibly interesting session at Black Hat titled “How I Met Your Girlfriend,” highlighted new types attacks executed from the Web.

Black Hat - How I met your GirlfriendSamy Kamkar, in an incredibly interesting session at Black Hat titled “How I Met Your Girlfriend,” highlighted new types attacks executed from the Web. During his talk Kamkar demonstrated how to extract extremely accurate geo-location information from a Web browser, while not using any IP geo-location data.

Kamkar, by convincing the victim to visit his malicious Web site, used remote JavaScript and AJAX to acquire a routers MAC address. When the unsuspecting user visited his malicious Web site, JavaScript remotely scanned for the type of router used, accessed the routers MAC address and sent it directly to him. From there, he was able to utilize Google Street View data to determine the location of a router – in his case, accurate within 30 feet.

Kamkar, author of an XSS worm that hit MySpace and generated over 1mm friends for him in less than 24 hours, demonstrates this hack in the video below.

Video of Samy Kamkar demonstrating the geolocation hack from his talk at Black Hat 2010 last week in Las Vegas.

Subscribe to SecurityWeek by RSS (Opens New Window)

Related Video: Barnaby Jack Demonstrates ATM Hacking at Black Hat

Advertisement. Scroll to continue reading.
Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

John Opala has joined Ralph Lauren as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.