One thing is unclear to me is, how does sending the credentials to statcounter work for the attacker? How would they recover the credentials afterwards? Assuming the statcounter website itself has not turned bad of course.
I can think about two potential ways but I have no idea if it's any of those:
- Very detailed filter to the point of seeing individual requests and so the token in the referrer URL.
- The referrer URL is the one that is actually getting the info, so when statcounter tries to crawl it then it will send the credentials there.
I can think about two potential ways but I have no idea if it's any of those:
- Very detailed filter to the point of seeing individual requests and so the token in the referrer URL.
- The referrer URL is the one that is actually getting the info, so when statcounter tries to crawl it then it will send the credentials there.