Skip to content

GitLab

  • Menu
Projects Groups Snippets
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • T Tor Browser
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 1,249
    • Issues 1,249
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 6
    • Merge requests 6
  • Deployments
    • Deployments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • Repository
  • Wiki
    • Wiki
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • The Tor Project
  • Applications
  • Tor Browser
  • Issues
  • #30427

Closed
Open
Created May 07, 2019 by Georg Koppen@gkDeveloper

Tor Bowser locale can be detected with FTP

xiaoyinl reported on HackerOne that the Tor Browser locale can be detected with FTP:

If a visitor navigates to a directory on a FTP server, Tor Browser shows a page displaying the directory tree. However, the source code of this page is generated by Tor Browser, rather than the server, because an FTP server only sends file info and the browser displays it in a nice format. Moreover, the FTP directory page is localized, even if the user has chosen not to reveal his/her UI language, i.e. privacy.spoof_english == 2.
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking