Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Google Chrome leaks DNS data queries outsitde of proxy if dns pre-fetching is enabled
From: nixlists <nixmlists () gmail com>
Date: Mon, 14 Dec 2009 20:45:12 +0000

Google Chrome has DNS pre-fetching feature enabled by
default. If a user is using Chrome with a proxy, the DNS queries must
go through the proxy by design, but with the DNS pre-fetching enabled
they are still sent to the system's configured DNS cache.

This seems also true for the SOCKS proxy in Chromium regardless of
whether DNS pre-fetching is enabled or not as shown here:


I have not verified the SOCKS proxy issue.

This presents a serious risk for the users of the services such as
Tor, as their DNS data and the little anonymity they have with tor is
leaked outside and in the clear.

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]