Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add ISO-3166 country codes #2939

Closed
wants to merge 2 commits into from
Closed

Conversation

colleirose
Copy link
Contributor

Adds ISO-3166 country codes to the low entropy cookie values

@ghostwords
Copy link
Member

ghostwords commented Jan 10, 2024

Hello! Right now the list mostly consists of a bunch of language codes. What made you consider adding country codes?

@colleirose
Copy link
Contributor Author

Well, many websites ask you to input your country, for example so that it can show you the version of the site for your area or something like that. A country code alone isn't enough to identify someone and there can be legitimate reasons for collecting it similarly to languages

@ghostwords
Copy link
Member

I see, thank you. Was there a specific website or websites that made you think of this?

@colleirose
Copy link
Contributor Author

Yes, I've remembered running into country codes in cookie values before but I don't know how often this is, the most recent one would be a website I found when doing a reverse image search in a CTF and clicking a website in the results and thinking to check the cookie values out of curiosity (I don't remember the name of the site but I can try to find it again when I have more free time), it seems like something that most websites would do but I don't know for sure, I'm unsure how to test a hypothesis like this because I don't have a tool to scan the Internet for common cookies or something to that effect

@colleirose colleirose closed this by deleting the head repository May 19, 2024
@ghostwords ghostwords added the heuristic Badger's core learning-what-to-block functionality label May 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
heuristic Badger's core learning-what-to-block functionality
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants