SkillAgentSearch skills...

Sniffly

Sniffing browser history using HSTS

Install / Use

/learn @diracdeltas/Sniffly
About this skill

Quality Score

0/100

Supported Platforms

Universal

README

Sniffly2

Sniffly2 is a variant of Sniffly which abuses HTTP Strict Transport Security headers and the Performance Timing API in order to sniff your browsing history in Chromium-based browsers.

Demo

Visit http://diracdeltas.github.io/sniffly in Chrome/Chromium/Brave/etc. with HTTPS Everywhere disabled.

Caveats:

  • does not work on mobile or Firefox
  • does not work over HTTPS due to mixed content blocking.
  • adblockers may taint results

Acknowledgements

  • crbug436451, reported by imfaster...@gmail.com, for the idea of probing port 443 over HTTP
  • Scott Helme for providing an initial list of HSTS hosts

Related Skills

View on GitHub
GitHub Stars937
CategoryDevelopment
Updated8d ago
Forks106

Languages

JavaScript

Security Score

95/100

Audited on Mar 21, 2026

No findings