This demonstration highlights how easily a website can collect technical and environmental information about its visitors without requiring any interaction from the user. By combining browser characteristics, device capabilities, network hints, and system configuration data, an attacker can build a surprisingly accurate fingerprint of a device. These signals can often reveal the type of device, operating system, manufacturer, and usage context, making it possible to narrow down or even identify specific individuals. Once this reconnaissance phase is complete, the collected information can be leveraged to craft highly targeted attacks such as spear-phishing, tailored social-engineering campaigns, credential-harvesting pages, or platform-specific malware delivery. The purpose of this demo is to raise awareness of how much passive information modern browsers expose and how easily it can be weaponized by an attacker during the early stages of an intrusion.
| Time (UTC) | Project | IP | Origin | OS / Browser | Device | Locale | Payload |
|---|