Анализ сайта spookjs.com
Основное Готовность: 100%
Домен
spookjs.com
Состояние доменного имени
?
Проверяем корректность доменного имени и наличие технических проблем на уровне домена.
Домен второго уровня идеален для продвижения.
Отличный запоминающийся домен.
Ответ сервера
200 Успешный ответ
HTTP-код ответа и цепочка редиректов
?
Код 200 — страница доступна. Коды 3xx — редиректы (цепочки замедляют загрузку и размывают ссылочный вес). Коды 4xx/5xx — ошибки, поисковик не сможет проиндексировать страницу.
Сервер настроен корректно.
Цепочка редиректов:
http://spookjs.com
301 MovedPermanently
https://www.spookjs.com/
200 OK
Безопасность
Сайт безопасен
Использование HTTPS и SSL-сертификат
?
HTTPS — обязательный стандарт. Google и Яндекс отдают предпочтение защищённым сайтам. Отсутствие SSL или просроченный сертификат ведут к предупреждениям в браузере и снижению позиций.
На сайте работает защищенный протокол ssl и сайт открывается по https.
Ssl-сертификат действителен до 19.11.2026 22:19:21.
Включён HSTS (Strict-Transport-Security) — защита от подмены на http.
HTTP автоматически перенаправляется на HTTPS.
Поздравляем! Сайт не содержится в реестре РКН.
Кодировка
utf-8
Кодировка символов страницы
?
Стандарт — UTF-8. Неправильная кодировка вызывает нечитаемые символы и мешает поисковику корректно распознать текст страницы.
Указана кодировка на странице utf-8.
Язык
en
Атрибут lang в HTML-теге
?
Атрибут lang (<html lang="ru">) сообщает поисковикам и браузерам, на каком языке написана страница. Помогает при ранжировании в региональном поиске.
Язык документа указан явно: en.
Скорость загрузки
~0,50сек
Время отклика сервера (TTFB)
?
Time To First Byte — время до получения первого байта от сервера. Норма до 200 мс. Медленный отклик ухудшает пользовательский опыт и ранжирование: Яндекс и Google учитывают скорость страниц.
Скорость загрузки сайта 0,50сек оптимальна.
Объем документа
40Кб
Размер HTML-кода страницы
?
Слишком большой HTML замедляет парсинг браузером и сканирование поисковым роботом. Рекомендуется не более 200 Кб.
Объем html-документа 40Кб оптимален.
Структура html-документа корректна.
Ресурсы
Ресурсы: 9
Внешние ресурсы страницы (CSS, JS, изображения)
?
Количество и тип подключённых ресурсов влияют на скорость загрузки. Большое число запросов увеличивает время рендеринга страницы.
Кол-во файлов ресурсов 9 достаточно.
Показать полный список ресурсов
| Тип | Название | Значение |
|---|---|---|
| stylesheet | https://cdn.jsdelivr.net/npm/bootstrap@5.1.0/dist/css/bootstrap.min.css | |
| stylesheet | text/css | https://stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css |
| stylesheet | https://fonts.googleapis.com/css2?family=Roboto:wght@300&display=swap | |
| stylesheet | css/theme.css | |
| js | https://www.googletagmanager.com/gtag/js?id=G-NN9P1066KJ | |
| js | https://cdn.jsdelivr.net/npm/bootstrap@5.1.0/dist/js/bootstrap.bundle.min.js | |
| js | https://code.jquery.com/jquery-3.4.1.slim.min.js | |
| js | https://cdn.jsdelivr.net/npm/popper.js@1.16.0/dist/umd/popper.min.js | |
| js | https://stackpath.bootstrapcdn.com/bootstrap/4.4.1/js/bootstrap.min.js |
Серверные заголовки
Кол-во: 18
HTTP-заголовки ответа сервера
?
Заголовки сервера передают браузеру и поисковику служебную информацию: кеширование, безопасность (CSP, HSTS), сжатие (gzip). Правильная настройка ускоряет загрузку и повышает защищённость.
Найдены серверные заголовки 18шт. Подробнее про серверные заголовки.
Показать полный список серверных заголовков
| Ключ | Значение |
|---|---|
| Server | GitHub.com |
| Access-Control-Allow-Origin | * |
| Strict-Transport-Security | max-age=31556952 |
| ETag | "637413b5-a3f3" |
| Cache-Control | max-age=600 |
| x-proxy-cache | MISS |
| x-github-request-id | 9C9C:1C389F:32A71E:369450:6A8A23DA |
| x-github-edge-region | swedencentral |
| Accept-Ranges | bytes |
| Age | 0 |
| Date | Sat, 22 Aug 2026 22:34:02 GMT |
| Via | 1.1 varnish |
| X-Served-By | cache-bma-essb1270046-BMA |
| X-Cache | MISS |
| x-cache-hits | 0 |
| x-timer | S1787438042.226121,VS0,VE114 |
| Vary | Accept-Encoding |
| x-fastly-request-id | bd7372997c6856495312d2d78ae472a9565ad5bc |
CMS
Не определена
Система управления сайтом (движок)
?
CMS — это движок, на котором работает сайт (WordPress, 1C-Bitrix, Tilda и др.). Знание CMS помогает понять возможности SEO-оптимизации и подобрать подходящие инструменты. «Не определена» — вероятно, самописный сайт или нестандартная сборка.
CMS не определена. Вероятно, сайт самописный либо движок надёжно скрыт. Это не ошибка.
Веб-сервер
GitHub.com
Программное обеспечение сервера
?
Веб-сервер — это ПО, которое отдаёт страницы посетителям (nginx, Apache, IIS, LiteSpeed и др.). Определяется по серверным заголовкам ответа (Server, X-Powered-By и т.п.). «Не определён» — сервер намеренно скрывает эти заголовки, это нормальная практика безопасности.
В заголовке Server указано: GitHub.com.
Мета-теги Готовность: 32%
Title
Spook.js
Заголовок страницы в браузере и поисковой выдаче
?
Title — главный SEO-заголовок страницы. Влияет на CTR в поиске и ранжирование. Оптимальная длина: 50–70 символов. Ключевые слова — ближе к началу.
Необходимо увеличить число символов в title (текущее значение мало: 8, минимум: 25, оптимально: от 40 до 45)
Дублей словоформ в title не найдено.
Description
Описание страницы в поисковой выдаче (сниппет)
?
Meta Description — текст под заголовком в выдаче. Напрямую на позиции не влияет, но влияет на CTR. Оптимальная длина: 120–160 символов.
Установите мета-тег description!
Keywords
Список ключевых слов страницы (устаревший тег)
?
Meta Keywords не учитывается Яндексом и Google для ранжирования с 2009–2012 годов. Заполнение не обязательно, но не вредит. Конкурент может использовать содержимое для анализа.
Установите мета-тег keywords!
Канонический Url
Указывает поисковику основную версию страницы
?
Canonical (rel=canonical) предотвращает проблему дублей страниц. Должен точно совпадать с URL проверяемой страницы. Неправильный canonical может передать ссылочный вес на другую страницу.
Рекомендуем прописать канонический Url.
Robots
Ошибок нет
Директивы для поисковых роботов на уровне страницы
?
Meta Robots управляет индексацией конкретной страницы: index/noindex — индексировать ли, follow/nofollow — следовать ли по ссылкам. Noindex полностью исключает страницу из поиска.
Meta-тег robots не указан. Страница свободна для индексации.
Адаптивность
width=device-width, initial-scale=1, shrink-to-fit=no
Настройка масштабирования на мобильных устройствах
?
Тег viewport (<meta name="viewport">) сообщает браузеру, как масштабировать страницу на мобильных. Стандарт: width=device-width, initial-scale=1. Отсутствие — признак отсутствия мобильной версии.
Meta-тег viewport со значением-константой width=device-width задаёт ширину страницы в соответствии с размером экрана.
Meta-тег viewport со значением initial-scale=1.0 определяет масштаб 1:1, т.е. «не масштабировать».
Разметка OpenGraph
Не найдено
Мета-теги для красивых превью в соцсетях
?
OpenGraph (og:title, og:description, og:image) управляет тем, как страница выглядит при репосте в социальных сетях и мессенджерах. Отсутствие OG-тегов — невзрачный превью при шеринге.
Разметка OpenGraph не задана. Страница не оптимизирована под социальные сети. Мета-теги с разметкой Og помогают социальным роботам лучше структурировать Ваш сайт.
Все мета-теги
Кол-во: 1
Полный список мета-тегов страницы
?
Таблица всех meta-тегов, включая нестандартные. Позволяет найти опечатки, дубли и лишние теги.
Найдены мета-теги 1шт. Мета-теги не видимы для человека и предназначены для обмена информацией между веб-страницей и поисковыми системами, браузерами и другими веб-службами. С ними роботы 🤖 и устройства ведут себя более ожидаемо.
Показать полный список мета-тегов
| Тип | Название | Значение |
|---|---|---|
| name | viewport | width=device-width, initial-scale=1, shrink-to-fit=no |
Оптимизация Готовность: 72%
Структура
Ошибок нет
Семантические HTML-элементы страницы
?
Проверяет наличие основных структурных элементов: nav, header, footer, main. Корректная семантическая структура помогает поисковику понять архитектуру страницы.
Структура документа корректна (теги <html> и <body> присутствуют в одном экземпляре).
Контент
Есть ошибки
Объём и качество текстового содержимого
?
Анализирует объём полезного текста на странице. Слишком мало — страница может считаться малополезной. Слишком много — ухудшается читаемость и восприятие.
Слова из title 1 встречаются в тексте редко. Добавьте в контент страницы слова из тега <title>!
Абзацев с текстом 28 достаточно.
Среднее число слов в абзаце 66 достаточно.
Кол-во знаков контента 17841 на странице оптимально.
Кол-во слов 2716 на странице оптимально.
Заголовки
Ошибок нет
Иерархия заголовков H1–H6
?
H1 должен быть один и содержать ключевой запрос. H2–H6 описывают подразделы. Пропуск уровней (H1 → H3) и несколько H1 — типичные ошибки, снижающие понятность страницы для поисковика.
На странице присутствуют заголовки <h1> 1. Это прекрасно.
На странице присутствуют заголовки <h2> 21. Это хорошо.
На странице присутствуют заголовки <h3> 1.
Тошнота
4,80
Насколько одно слово доминирует в тексте
?
Классическая тошнота = √(частота самого повторяющегося слова). Норма до 7–8: текст воспринимается естественно. Выше — поисковик может счесть страницу переспамленной.
Тошнота страницы в пределах нормы 4,80.
Академич. тошнота
27,03%
Насколько текст перенасыщен ключевыми словами
?
Академическая тошнота = (частота слова / общее количество слов) × 100%. Показывает долю конкретного слова в тексте. Норма 5–15%.
Академическая тошнота превышает норму 5-15%. Измените текст страницы!
Семантическое ядро
20
Наиболее часто встречающиеся слова на странице
?
Топ слов по частоте использования. Показывает, какие слова доминируют в тексте с точки зрения поисковика.
Контент страницы содержит осмысленный текст и слова.
Показать список слов
| Слово | Кол-во | Частота |
|---|---|---|
| chrome | 23 | 0,85% |
| isolation | 19 | 0,70% |
| strict | 18 | 0,66% |
| information | 17 | 0,63% |
| different | 15 | 0,55% |
| domain | 14 | 0,52% |
| credential | 13 | 0,48% |
| process | 13 | 0,48% |
| browser | 11 | 0,41% |
| extension | 11 | 0,41% |
| execution | 10 | 0,37% |
| attack | 10 | 0,37% |
| spectre | 10 | 0,37% |
| websites | 10 | 0,37% |
| speculative | 9 | 0,33% |
| javascript | 9 | 0,33% |
| sensitive | 9 | 0,33% |
| chrome's | 8 | 0,29% |
| channel | 8 | 0,29% |
| extensions | 8 | 0,29% |
Индексация Готовность: 30%
Индексирование
Ошибок нет
Разрешено ли индексирование страницы
?
Проверяет, не закрыта ли страница от индексации через robots.txt, meta robots или X-Robots-Tag. Страница, закрытая от индексации, не появится в поисковой выдаче.
Анкоров на странице 28 оптимально. Поисковые роботы обязательно проиндексируют сайт.
Robots.txt
Найден корректный robots.txt
Файл управления сканированием сайта роботами
?
Robots.txt указывает поисковым роботам, какие страницы сканировать, а какие — нет. Ошибки в файле могут случайно закрыть важные разделы от индексации.
Robots.txt настроен корректно. Размер файла: 41971 байт. Загружен за: 1сек.
Проверяемая страница не запрещена в robots.txt.
Robots.txt доступен по постоянному адресу
Цепочка редиректов для файла robots.txt:
http://spookjs.com/robots.txt
301 MovedPermanently
https://www.spookjs.com/
200 OK
Показать содержимое robots.txt
<!doctype html>
<html lang="en">
<head>
<!-- Global site tag (gtag.js) - Google Analytics -->
<script async src="https://www.googletagmanager.com/gtag/js?id=G-NN9P1066KJ"></script>
<script>
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
gtag('js', new Date());
gtag('config', 'G-NN9P1066KJ');
</script>
<script>
function copy_to_clipboard() {
/* Get the text field */
var copyText = document.getElementById("citeTextarea");
/* Select the text field */
copyText.select();
copyText.setSelectionRange(0, 99999); /*For mobile devices*/
/* Copy the text inside the text field */
document.execCommand("copy");
/* Alert the copied text */
/*alert("Copied the text: " + copyText.value);*/
}
</script>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
<!-- Bootstrap and Font-Awesome -->
<link href="https://cdn.jsdelivr.net/npm/bootstrap@5.1.0/dist/css/bootstrap.min.css" rel="stylesheet"
integrity="sha384-KyZXEAg3QhqLMpG8r+8fhAXLRk2vvoC2f3B09zVXn8CA5QIVfZOJ3BCsw2P0p/We" crossorigin="anonymous">
<script src="https://cdn.jsdelivr.net/npm/bootstrap@5.1.0/dist/js/bootstrap.bundle.min.js"
integrity="sha384-U1DAWAznBHeqEIlVSCgzq+c9gqGAJn5c/t99JyeKa9xxaYpSvHU5awsuZVVFIhvj"
crossorigin="anonymous"></script>
<link href="https://stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css" type="text/css"
rel="stylesheet">
<!-- Google Fonts -->
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Roboto:wght@300&display=swap" rel="stylesheet">
<link href="css/theme.css" rel="stylesheet">
<title>Spook.js</title>
</head>
<body>
<div class="jumbotron">
<div class="container">
<div class="row align-items-center">
<div class="col-sm-3">
<img style="max-height: 150px; max-width: 100%; margin: auto; display: block;"
src="img/spook-js.svg" id="logo" alt="Spook.js Logo" />
</div>
<div class="col-sm-8">
<h1 class="text-center">Spook.js</h1>
<h3 class="text-center">Attacking Google Chrome's Strict Site Isolation via Speculative
Execution and Type Confusion</h3>
</div>
<div class="col-sm-1"></div>
</div>
</div>
</div>
<div class="container">
<section id="abstract">
<h4><i class="fa fa-chrome" style="padding-right: 10px;"></i>What is it?</h4>
<div class="container">
<p>
Spook.js is a new transient execution side channel attack which targets the Chrome web browser.
We show that despite Google's attempts to mitigate <a
href="https://spectreattack.com/">Spectre</a> by deploying <a
href="https://www.chromium.org/Home/chromium-security/site-isolation">Strict Site
Isolation</a>, information extraction via malicious JavaScript code is still possible in
some cases.
</p>
<p>
More specifically, we show that an attacker-controlled webpage can know which other pages from
the same websites a
user is currently browsing, retrieve sensitive information from these pages, and even recover
login credentials (e.g., username and password) when they are autofilled. We further demonstrate
that the attacker
can retrieve data from Chrome extensions (such as credential managers)
if a user installs a malicous extension.
</p>
<div class="row" style="padding-top: 10px; text-align: center;">
<div class="col-xs-12 button-wrapper">
<a href="files/spook-js.pdf" target="_blank" class="btn btn-primary mr-2" style="margin-right: 10px;"><i
class="fa fa-download" style="padding-right: 10px;"></i>Download the Paper (PDF)</a>
<a href="#" class="btn btn-primary" data-toggle="modal" data-target="#cite-spookjs"><i
class="fa fa-quote-left" style="padding-right: 10px;"></i> Cite (BibTeX)</a>
</div>
</div>
<div class="modal fade" id="cite-spookjs" tabindex="-1" role="dialog"
aria-labelledby="exampleModalCenterTitle" aria-hidden="true">
<div class="modal-dialog modal-dialog-centered modal-lg" role="document">
<div class="modal-content">
<div class="modal-header">
<h5 class="modal-title" id="exampleModalLongTitle">Cite Spook.js</h5>
</div>
<div class="modal-body">
<textarea class="form-control rounded-0" id="citeTextarea" rows="8" readonly>
@inproceedings{spookjs,
title = {Spook.js: Attacking Chrome Strict Site Isolation via Speculative Execution},
author = {Ayush Agarwal and Sioli O'Connell and Jason Kim and Shaked Yehezkel and Daniel Genkin and Eyal Ronen and Yuval Yarom},
booktitle = {43rd IEEE Symposium on Security and Privacy (S\&P'22)},
year = {2022},
}
</textarea>
</div>
<div class="modal-footer">
<a href="javascript:copy_to_clipboard()" class="btn btn-primary mr-auto"><i
class="fa fa-clipboard" style="margin-right: 10px;" aria-hidden="true"></i>
Copy to Clipboard</a>
<button type="button" class="btn btn-secondary" data-dismiss="modal">Close</button>
</div>
</div>
</div>
</div>
</div>
</section>
<section id="demos">
<h4><i class="fa fa-exclamation-triangle" style="padding-right: 10px;"></i>What can Spook.js do?</h4>
<div class="container">
<h5 class="green">Attacking Tumblr with Chrome's Built-in Credential Manager</h5>
<p>
We deployed Spook.js on a Tumblr blog, targeting a password that was autofilled into Tumblr's
login page by Chrome's built-in credential manager. We show that our blog can be rendered by the
same Chrome process as the login page, and that Spook.js can consequently recover the password.
</p>
<iframe width="560" height="315" src="https://www.youtube-nocookie.com/embed/bP9Hquj5PH4" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe>
<h5 class="green" style="margin-top: 20px;">Attacking LastPass with a Malicious Chrome Extension</h5>
<p>
This time, we packaged Spook.js as a Chrome extension. We show that under certain conditions,
multiple extensions may be consolidated and executed from the same process. We take advantage
of this behavior to read the memory of the LastPass credential manager extension, and recover
the master password of the target's vault.
</p>
<iframe width="560" height="315" src="https://www.youtube-nocookie.com/embed/yz_s4k1zGwA" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe>
</div>
</section>
<section id="people">
<h4 style="padding-top: 20px;"><i class="fa fa-users" style="padding-right: 10px;"></i>Who are the people behind Spook.js?</h4>
<div class="container">
<ul>
<li><a href="https://www.linkedin.com/in/agarwalayush9">Ayush Agarwal</a> <span class="badge badge-michigan"><a class="univ"
href="https://umich.edu/">University of Michigan</a></span></li>
<li>Sioli O'Connell <span class="badge badge-adelaide"><a class="univ"
href="https://www.adelaide.edu.au/">University of Adelaide</a></span></li>
<li><a href="https://jasonkim.page/">Jason Kim </a><span class="badge badge-gatech"><a class="univ"
href="https://www.gatech.edu/">Georgia Institute of Technology</a></span></li>
<li>Shaked Yehezkel <span class="badge badge-tau"><a class="univ"
href="https://english.tau.ac.il/">Tel Aviv University</a></span></li>
<li><a href="https://www.cc.gatech.edu/~genkin/">Daniel Genkin</a> <span class="badge badge-gatech"><a class="univ"
href="https://www.gatech.edu/">Georgia Institute of Technology</a></span></li>
<li><a href="https://eyalro.net/">Eyal Ronen</a> <span class="badge badge-tau"><a class="univ"
href="https://english.tau.ac.il/">Tel Aviv University</a></span></li>
<li><a href="https://cs.adelaide.edu.au/~yval">Yuval Yarom</a> <span class="badge badge-adelaide"><a class="univ"
href="https://www.adelaide.edu.au/">University of Adelaide</a></span></li>
</ul>
<p style="text-align: center;"><b>Contact us at <a href="mailto:info@spookjs.com">info@spookjs.com</a></b></p>
<br>
<div class="row align-items-center" style="margin-top: -20px; margin-bottom: -20px;">
<div class="col-sm-1"></div>
<div class="col-sm-3" style="text-align: center;">
<img class="img-fluid" src="img/gatech.png" alt="Georgia Institute of Technology"
style="padding: 10px; max-height: 100px;" />
</div>
<div class="col-sm-2" style="text-align: center;">
<img class="img-fluid" src="img/adelaide.svg" alt="University of Adelaide"
style="padding: 10px; max-height: 100px;" />
</div>
<div class="col-sm-2" style="text-align: center;">
<img class="img-fluid" src="img/umich.png" alt="University of Michigan"
style="padding: 10px; max-height: 80px;" />
</div>
<div class="col-sm-3" style="text-align: center;">
<img class="img-fluid" src="img/tau.png" alt="Tel Aviv University"
style="padding: 10px; max-height: 100px;" />
</div>
<div class="col-sm-1"></div>
</div>
</div>
</section>
<section id="qa">
<h4 style="padding-top: 20px;"><i class="fa fa-question-circle" style="padding-right: 10px;"></i>More Questions and Answers</h4>
<div class="container">
<h5 class="green">Impact and Potential Concerns</h5>
</div>
<div class="accordion accordion-flush" id="impact-and-potential-concerns" style="padding-top: 10px;">
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingAffected">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseAffected" aria-expanded="false"
aria-controls="panelsStayOpen-collapseAffected">
Have I been affected by this attack?
</button>
</h2>
<div id="panelsStayOpen-collapseAffected" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingAffected">
<div class="accordion-body">
If you have an Intel processor or an Apple device with the M1 chip, then yes with very
high probability. We also expect our attack to be effective for AMD machines, however
this has been only partially demonstrated.
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingImpact">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseImpact" aria-expanded="false"
aria-controls="panelsStayOpen-collapseImpact">
What is the impact of this attack?
</button>
</h2>
<div id="panelsStayOpen-collapseImpact" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingImpact">
<div class="accordion-body">
Under certain conditions, malicious JavaScript code running in one Chrome browser tab can read the
contents being displayed on another Chrome tab, which might contain sensitive information
such as passwords, bank details, etc. Furthermore, malicious extensions might be able to
read the contents of other extensions, including sensitive information stored
inside them (e.g., passwords inside credential managers).
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingLeaked">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseLeaked" aria-expanded="false"
aria-controls="panelsStayOpen-collapseLeaked">
What other information can be leaked?
</button>
</h2>
<div id="panelsStayOpen-collapseLeaked" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingLeaked">
<div class="accordion-body">
Anything stored in the memory of a website being rendered or a Chrome extension is fair game.
In our evaluation, we have demonstrated leakage of the following information:
<ul>
<li>The list of same-site tabs which a user currently has open</li>
<li>Phone numbers, addresses, and bank account information displayed on a website
</li>
<li>Usernames, passwords, and credit card numbers autofilled by credential managers
</li>
<li>Under certain circumstances, images in Google Photos which a user is currently viewing</li>
<li>Information sensitive to an individual Chrome extension, such as its login
information</li>
</ul>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingAbuse">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseAbuse" aria-expanded="false"
aria-controls="panelsStayOpen-collapseAbuse">
Has Spook.js been abused in the wild?
</button>
</h2>
<div id="panelsStayOpen-collapseAbuse" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingAbuse">
<div class="accordion-body">
We do not have any evidence so far that Spook.js has been or not
been abused in the wild.
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingDetect">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseDetect" aria-expanded="false"
aria-controls="panelsStayOpen-collapseDetect">
Can I detect if someone has used Spook.js against me?
</button>
</h2>
<div id="panelsStayOpen-collapseDetect" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingDetect">
<div class="accordion-body">
It is highly unlikely, because the attack code runs in the browser and does not
leave traces in traditional system log files.
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingStopExtension">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseStopExtension" aria-expanded="false"
aria-controls="panelsStayOpen-collapseStopExtension">
Should I stop using Chrome extensions?
</button>
</h2>
<div id="panelsStayOpen-collapseStopExtension" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingStopExtension">
<div class="accordion-body">
<p>
No, you can continue using Chrome extensions. While we have found issues with Chrome's
extension isolation, Spook.js is still relatively hard to mount and
requires substantial side channel expertise. Moreover, in response to our work,
Google has deployed changes to how extensions are laid out in memory, which
prevents them from being affected by Spook.js. See the 'What countermeasures are
available?' question for more information.
</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingStopPassword">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseStopPassword" aria-expanded="false"
aria-controls="panelsStayOpen-collapseStopPassword">
Should I stop using credential managers?
</button>
</h2>
<div id="panelsStayOpen-collapseStopPassword" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingStopPassword">
<div class="accordion-body">
No, you can (and should!) continue using credential managers. While credential recovery
is possible, it can only happen if the attacker has obtained a webpage on the domain
associated with the credential. This limits the risk of credential theft, as most
websites do not allow users to upload webpages arbitrarily. On balance, not using
credential managers puts your passwords at much greater risk of being insecurly stored
and subsequently stolen.
</div>
</div>
</div>
</div>
<div class="container">
<h5 class="green">Technical Details</h5>
</div>
<div class="accordion accordion-flush" id="technical-details" style="padding-top: 10px;">
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingJS">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseJS" aria-expanded="false"
aria-controls="panelsStayOpen-collapseJS">
What is JavaScript?
</button>
</h2>
<div id="panelsStayOpen-collapseJS" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingJS">
<div class="accordion-body">
JavaScript is a programming language understood by web browsers, making it one
of the core components of the web. It is used by interactive websites such as
social media, e-commerce, and games. While JavaScript-based side channel attacks are
harder to design and implement, they are much more dangerous as browsers execute
JavaScript code automatically and without any user interaction. In particular,
JavaScript-based attacks do not require the user to run any malicious software on their
devices.
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingSpeculative">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseSpeculative" aria-expanded="false"
aria-controls="panelsStayOpen-collapseSpeculative">
What is Speculative Execution?
</button>
</h2>
<div id="panelsStayOpen-collapseSpeculative" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingSpeculative">
<div class="accordion-body">
<p>
Modern processors improve performance by predicting if a branch in program code
will be taken or not, especially if the branch's condition cannot be computed yet.
If a processor predicts that a branch will be taken, it will speculatively start
executing the instructions within the branch, even though
it has not calculated the outcome of the branch. If the branch is actually taken,
its instructions have been partially computed already, bringing in the performance
benefits. On the contrary, if the branch is actually not taken, the processor
attempts to roll back
the instructions it speculatively executed.
</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingSidechannel">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseSidechannel" aria-expanded="false"
aria-controls="panelsStayOpen-collapseSidechannel">
What is a Side Channel Attack?
</button>
</h2>
<div id="panelsStayOpen-collapseSidechannel" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingSidechannel">
<div class="accordion-body">
<p>
The majority of attacks on computer systems take advantage of vulnerabilities in the
algorithms they use. For example, they exploit bugs, buffer overflows or bad random number generators in order to break the security of the targeted system.
In contrast, a side channel attack leverages the hardware of the system in order to attack it. Common side channel examples include monitoring the system's power consumption, electromagnetic radiation, and even sound.
</p>
<p>
One popular source of side channels (which we also use for Spook.js) is the processor's cache. The cache is a hardware component which stores recently used data in memory to
provide faster access. Although this speeds up performance, an attacker can measure the time it takes to retrieve certain data and thus infer if another program has accessed it. This allows the attacker to retrieve the target's memory access pattern, which in many cases is highly correlated with the data processed by the target. Finally, cache side channels are useful as a building block in speculative and transient execution attacks, such as Spook.js, Spectre and Meltdown.
</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingSpectre">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseSpectre" aria-expanded="false"
aria-controls="panelsStayOpen-collapseSpectre">
What is Spectre?
</button>
</h2>
<div id="panelsStayOpen-collapseSpectre" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingSpectre">
<div class="accordion-body">
<p>
<a href="https://spectreattack.com/">Spectre</a> is a hardware vulnerability that
affects nearly every general purpose processor. This includes nearly all modern
Intel, AMD, and Apple CPUs, both for desktops and laptops. At a high level, the
majority of recent processors predict the outcome of a branch if it cannot be
computed quickly, and continue executing instructions along the prediction. If the
prediction is incorrect, the processor must roll back the instructions it executed
speculatively, alongside any state changes incurred by these instructions.
</p>
<p>
However, speculative execution leaves traces in the CPU's microarchitectural state,
notably in the cache. Thus, a Spectre attacker might confuse the CPU's branch
predictor into incorrectly executing instructions that should not have been executed
otherwise. In case this incorrect speculation operates over private data, it is
possible to leak the data via a side channel thus allowing attackers to read data
otherwise inaccessible to them. In particular, in case a suitable Spectre-vulnerable
code pattern (gadget) is present in a process belonging to a targeted program, an
attacker might abuse this gadget in order to recover the contents of the process's
entire address space and the data within it. Being a fundamental issue with
speculative execution, Spectre is a threat to nearly all software, ranging from the
computer's operating system to the web browser.
</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingSiteiso">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseSiteiso" aria-expanded="false"
aria-controls="panelsStayOpen-collapseSiteiso">
What is Strict Site Isolation?
</button>
</h2>
<div id="panelsStayOpen-collapseSiteiso" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingSiteiso">
<div class="accordion-body">
<p>
Operating systems such as Windows, Linux, and macOS currently isolate different
programs into different units of execution called processes. The CPU then enforces
this isolation at the hardware level, preveting one process from accessing the
contents of other processes.
</p>
<p>
Strict Site Isolation is a recent browser architecture aimed at increasing browser
security. Rather then arbitrarily assign different websites into different
processes, browsers with Strict Site Isolation enabled ensure that content from
different websites will be located in different processes. For example, data
pertaining to google.com will never share the same process as the data for
wikipedia.org, thus ensuring that these websites are isolated from each other at the
hardware level.
</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingeTLD">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseeTLD" aria-expanded="false"
aria-controls="panelsStayOpen-collapseeTLD">
What is eTLD+1?
</button>
</h2>
<div id="panelsStayOpen-collapseeTLD" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingeTLD">
<div class="accordion-body">
<p>
eTLD+1 is an acronym for effective top-level domain plus one. A top-level domain
(TLD) is the part of a domain name without dots, such as "com", "org", or "edu".
Users can register domain names under a TLD, like "example.com".
On the other hand, an effective top-level domain (eTLD) contains dots and is
therefore not a true TLD, but is the part of a domain name under which subdomains
can be registered directly. An example is "edu.au", with "adelaide.edu.au" registered under it.
</p>
<p>
The +1 refers to the term that comes just before the TLD or eTLD, delimited
by a dot. That is, for "example.com" it is "example", and for "adelaide.edu.au" it
is "adelaide". If two websites share a TLD or eTLD as well as the term preceding it,
Chrome might consolidate them into the same process, despite Strict Site Isolation.
Thus, Chrome will separate "example.com" and "example.net" due to different TLDs, and also
"example.com" and "attacker.com" because the +1 terms (preceding the TLD) are different.
However, "attacker.example.com" and "corporate.example.com" are allowed to share the same
process due to their common eTLD+1 of "example.com". This allows pages hosted under "attacker.example.com"
to potentially extract information from pages under "corporate.example.com".
</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingSpectre">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseSpectreAttack" aria-expanded="false"
aria-controls="panelsStayOpen-collapseSpectreAttack">
If Strict Site Isolation was deployed to mitigate Spectre, why is a Spectre-class attack
still possible?
</button>
</h2>
<div id="panelsStayOpen-collapseSpectreAttack" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingSpectre">
<div class="accordion-body">
<p>
Spectre is fundamentally a hardware vulnerability where footprints of speculative
execution are not cleaned up completely within the processor's state. Thus, Strict Site
Isolation cannot fix Spectre. Instead, Strict Site Isolation attempts to limit
information leakage by separating
the contents of different websites into different processes.
</p>
<p>
However, there are certain conditions under which Chrome does not separate two
websites. The most prominent is the case where two websites sharing an eTLD+1 domain
are opened in separate tabs, while the system is already under memory pressure from
other tabs being open. In our paper, we identified several services which host
attacker-controlled JavaScript code on the same eTLD+1 domain as a page containing
sensitive information, such as the service's login page. In this example, in case
the user opens a page hosting Spook.js attack code in parallel to the service's login
page, Chrome's Strict Site Isolation implementation consolidates these two pages
into the same process. This then allows our attack to extract the user's
credentials as these are being autofilled by the browser's credential manager.
</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingDifference">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseDifference" aria-expanded="false"
aria-controls="panelsStayOpen-collapseDifference">
So what is different between Spook.js and Spectre?
</button>
</h2>
<div id="panelsStayOpen-collapseDifference" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingDifference">
<div class="accordion-body">
<p>
Since Spectre's original introduction in 2018, browser vendors have deployed many
countermeasures in order to make Spectre harder to exploit. In addition to Strict
Site Isolation, which prevets different webpages from sharing the same process,
Chrome also partitions the address space of each process into different 32-bit
sandboxes (despite being a 64-bit application). Limiting all values to be 32-bit
prevents a Spectre attacker from crossing partition boundaries, thus further
limiting information exposure.
</p>
<p>
Spook.js shows that these countermeasures are insufficient in order to protect users
from browser-based speculative execution attacks. More specifically, we show that
Chrome's Strict Site Isolation implementation consolidates webpages based on their
eTLD+1 domain, allowing an attacker-controlled page to extract sensitive information
from pages on other subdomains. Next, we also show how to bypass
Chrome's 32-bit sandboxing mechanism. We achieve this by using a type confusion
attack, which temporarily forces Chrome's JavaScript execution engine to operate on
an object of the wrong type. Using this method we can combine multiple 32-bit values
into a single 64-bit pointer, which allows us to read the process's entire address
space. Finally, going beyond initial proof-of-concepts, we demonstrate end-to-end
attacks extracting sensitive information such as the list of open pages, their
contents, and even login credentials.
</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingOther">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseOther" aria-expanded="false"
aria-controls="panelsStayOpen-collapseOther">
Are other web browsers also vulnerable?
</button>
</h2>
<div id="panelsStayOpen-collapseOther" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingOther">
<div class="accordion-body">
<p>
We have tested Spook.js on Chromium, which is the basis of the Chrome browser. Thus,
in addition to Chrome itself, we expect most Chromium-based browsers to be
vulnerable to some variant of Spook.js. This includes recent versions of Microsoft's
<a href="https://www.microsoft.com/en-us/edge">Edge</a> browser, as well as <a
href="https://brave.com/">Brave</a> which is a privacy-centered browser.
</p>
<p>
Other browsers like Firefox and Safari use very different JavaScript execution
engines, which currently stops Spook.js from working. We leave the task of
investigating speculative exection attacks on these browsers to future work.
Finally, Firefox has <a
href="https://blog.mozilla.org/security/2021/05/18/introducing-site-isolation-in-firefox/">recently
introduced</a> Strict Site Isolation in its stable release. While Spook.js does
not work on Firefox as is, we note that similarly to Chrome, Firefox also
consolidates pages based on their eTLD+1 domain.
</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingMitigation">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseMitigation" aria-expanded="false"
aria-controls="panelsStayOpen-collapseMitigation">
What countermeasures are available?
</button>
</h2>
<div id="panelsStayOpen-collapseMitigation" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingMitigation">
<div class="accordion-body">
<p>
Web developers can immediately separate untrusted, user-supplied JavaScript code
from all other content for their website, hosting all user-supplied JavaScript code
at a domain that
has a different eTLD+1. This way, Strict Site Isolation will not consolidate
attacker-supplied code with
potentially sensitive data into the same process, putting the data out of reach even
for Spook.js as it cannot cross process boundaries.
</p>
<p>
In addition, sites can register their domain name to the <a
href="https://publicsuffix.org/">Public Suffix
List</a> (PSL). The PSL is maintained by Mozilla, and
is a list of domains under which users can register names directly (even if the
domains are not true top-level domains). Chrome will not consolidate pages if their
eTLD+1 domain is present in the PSL. That is, x.publicsuffix.com and
y.publicsuffix.com will always be separated.
</p>
<p>
Finally, as a response to our work, Google introduced <a
href="https://security.googleblog.com/2021/07/protecting-more-with-site-isolation.html">
Strict Extension Isolation</a>, a feature which
prevents multiple extensions from being consolidated into the same process under memory
pressure. This stops Spook.js (packaged as a malicious extension) from reading the
memory of other extensions. Strict Extension Isolation is enabled as of Chrome versions 92 and up.
We also link a <a href="https://blog.chromium.org/2021/03/mitigating-side-channel-attacks.html">
blog post</a> by Google's Chromium Project on tips for web developers to defend their sites
against side channel attacks.
</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingTechnical">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseTechnical" aria-expanded="false"
aria-controls="panelsStayOpen-collapseTechnical">
Is there more technical information available?
</button>
</h2>
<div id="panelsStayOpen-collapseTechnical" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingTechnical">
<div class="accordion-body">
Yes, there is an academic paper available <a href="files/spook-js.pdf">here</a>, also
through the download button at the top of this webpage. It will appear at the 43rd IEEE
Symposium on Security and Privacy (S&P'22) in May 2022.
</div>
</div>
</div>
</div>
<div class="container">
<h5 class="green">Miscellaneous</h5>
</div>
<div class="accordion accordion-flush" id="miscellaneous" style="padding-top: 10px;">
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingPoC">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapsePoC" aria-expanded="false"
aria-controls="panelsStayOpen-collapsePoC">
Is there a proof-of-concept?
</button>
</h2>
<div id="panelsStayOpen-collapsePoC" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingPoC">
<div class="accordion-body">
<p>Yes, please see our GitHub <a href="https://github.com/spookjs/spookjs-poc">repository</a>.</p>
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingWhyattack">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseWhyattack" aria-expanded="false"
aria-controls="panelsStayOpen-collapseWhyattack">
Why did you attack Tumblr and LastPass?
</button>
</h2>
<div id="panelsStayOpen-collapseWhyattack" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingWhyattack">
<div class="accordion-body">
Our rationale for attacking Tumblr and LastPass simply arose from the fact that they are
a widely used website and Chrome extension respectively, and are likely to contain
sensitive information. As a disclaimer, we clarify that Spook.js exploits weaknesses in
the Strict Site Isolation mechanism of the Chrome browser, and does not rely on
vulnerabilities in either service. In particular, we do not discourage users from using
these services.
</div>
</div>
</div>
<div class="accordion-item">
<h2 class="accordion-header" id="panelsStayOpen-headingLogo">
<button class="accordion-button collapsed" type="button" data-bs-toggle="collapse"
data-bs-target="#panelsStayOpen-collapseLogo" aria-expanded="false"
aria-controls="panelsStayOpen-collapseLogo">
Can I use the logo?
</button>
</h2>
<div id="panelsStayOpen-collapseLogo" class="accordion-collapse collapse"
aria-labelledby="panelsStayOpen-headingLogo">
<div class="accordion-body">
<p>
Our Spook.js logo contains the logo of the Chromium project, which is
published under the
<a href="https://creativecommons.org/licenses/by/2.5/">Creative Commons Attribution 2.5 Generic</a>
(CC BY 2.5) license. We acknowledge that the Chromium logo belongs to
the Chromium project, maintained by Google. While we have not modified the
Chromium logo itself, we include it as a component of the Spook.js logo.
</p>
<p>
Accordingly, we release our logo under the same license. You can modify, redistribute, and copy it
freely. Logo (excluding the Chromium logo component) designed by Jason Kim (who had to teach himself a bit of
digital illustration just for it!)
</p>
</div>
</div>
</div>
</div>
</section>
<section id="acknowledgments">
<h4><i class="fa fa-comments" style="padding-right: 10px;"></i>Acknowledgments</h4>
<div class="block">
<p>
This work was supported by
the Air Force Office of Scientific Research (AFOSR) under award number FA9550-20-1-0425;
an ARC Discovery Early Career Researcher Award (project number DE200101577);
an ARC Discovery Project (project number DP210102670);
CSIRO's Data61;
the Defense Advanced Research Projects Agency (DARPA) and
Air Force Research Laboratory (AFRL) under contracts FA8750-19-C-0531 and HR001120C0087;
Israel Science Foundation grants 702/16 and 703/16;
the National Science Foundation under grant CNS-1954712;
Len Blavatnik and the Blavatnik Family foundation and Blavatnik ICRC at Tel-Aviv University;
Robert Bosch Foundation;
and gifts from Intel and AMD.
</p>
</div>
</section>
</div>
<footer>
<div class="text-center w-100">
<span>Copyright © Georgia Institute of Technology. All rights reserved.</span>
</div>
</footer>
<script src="https://code.jquery.com/jquery-3.4.1.slim.min.js"
integrity="sha384-J6qa4849blE2+poT4WnyKhv5vZF5SrPo0iEjwBvKU7imGFAV0wwj1yYfoRSJoZ+n"
crossorigin="anonymous"></script>
<script src="https://cdn.jsdelivr.net/npm/popper.js@1.16.0/dist/umd/popper.min.js"
integrity="sha384-Q6E9RHvbIyZFJoft+2mJbHaEWldlvI9IOYy5n3zV9zzTtmI3UksdQRVvoxMfooAo"
crossorigin="anonymous"></script>
<script src="https://stackpath.bootstrapcdn.com/bootstrap/4.4.1/js/bootstrap.min.js"
integrity="sha384-wfSDF2E50Y2D1uUdj0O3uMBJnjuUD4Ih7YwaYd1iqfktj0Uod8GCExl3Og8ifwB6"
crossorigin="anonymous"></script>
</body>
</html>
Sitemap
Кол-во: 0
XML-карта сайта для поисковиков
?
Sitemap.xml помогает поисковику быстрее находить и индексировать страницы. Особенно важен для крупных сайтов и новых страниц, на которые ещё нет входящих ссылок.
Robots.txt не содержит ссылку на карту сайта. Рекомендуется добавить карту сайта и указать ссылку на нее в robots.txt.
Внутренние ссылки
Кол-во: 2
Ссылки на другие страницы своего сайта
?
Внутренние ссылки распределяют ссылочный вес между страницами и помогают поисковику обходить сайт. Пустые анкоры и ссылки на запрещённые robots.txt страницы — типичные ошибки.
Внутренних ссылок на странице 2 оптимально.
Внутренние ссылки не запрещены к индексации в robots.txt.
Показать внутренние ссылки
| Url | Анкор | Состояние | Анализировать |
|---|---|---|---|
| /files/spook-js.pdf |
<i class="fa fa-download" style="padding-right: 10px;"></i>Download the Paper (PDF)
|
|
|
| /files/spook-js.pdf |
here
|
|
Внешние ссылки
Кол-во: 23
Ссылки на сторонние сайты
?
Исходящие внешние ссылки передают часть ссылочного веса на чужие сайты. Ссылки на авторитетные ресурсы безопасны; ссылки на мусорные сайты могут навредить репутации страницы.
Внешних ссылок на странице 23 слишком много. Спрячьте лишние ссылки в тег noindex или атрибут rel='nofollow'!
Показать внешние ссылки
| Url | Анкор | Анализировать |
|---|---|---|
| spectreattack.com |
Spectre
|
Анализировать url |
| chromium.org |
Strict Site
Isolation
|
Анализировать url |
| linkedin.com |
Ayush Agarwal
|
Анализировать url |
| umich.edu |
University of Michigan
|
Анализировать url |
| adelaide.edu.au |
University of Adelaide
|
Анализировать url |
| jasonkim.page |
Jason Kim
|
Анализировать url |
| gatech.edu |
Georgia Institute of Technology
|
Анализировать url |
| english.tau.ac.il |
Tel Aviv University
|
Анализировать url |
| cc.gatech.edu |
Daniel Genkin
|
Анализировать url |
| gatech.edu |
Georgia Institute of Technology
|
Анализировать url |
| eyalro.net |
Eyal Ronen
|
Анализировать url |
| english.tau.ac.il |
Tel Aviv University
|
Анализировать url |
| cs.adelaide.edu.au |
Yuval Yarom
|
Анализировать url |
| adelaide.edu.au |
University of Adelaide
|
Анализировать url |
| spectreattack.com |
Spectre
|
Анализировать url |
| microsoft.com |
Edge
|
Анализировать url |
| brave.com |
Brave
|
Анализировать url |
| blog.mozilla.org |
recently
introduced
|
Анализировать url |
| publicsuffix.org |
Public Suffix
List
|
Анализировать url |
| security.googleblog.com |
Strict Extension Isolation
|
Анализировать url |
| blog.chromium.org |
blog post
|
Анализировать url |
| github.com |
repository
|
Анализировать url |
| creativecommons.org |
Creative Commons Attribution 2.5 Generic
|
Анализировать url |
Конкуренты Готовность: 0%
Конкуренты в Яндексе
Кол-во: 0
Топ сайтов-конкурентов в Яндексе
?
Сайты, чаще всего появляющиеся в ТОПе Яндекса по запросам из семантического ядра этой страницы.
Мы не нашли у вас конкурентов в Яндексе. Сайт или очень молодой или плохо продвигается.
Конкурентов в ТОП-10 Яндекса не нашлось.
Конкуренты в Google
Кол-во: 0
Топ сайтов-конкурентов в Google
?
Сайты, чаще всего появляющиеся в ТОПе Google по запросам из семантического ядра этой страницы.
Конкуренты в Google тоже не найдены. Займитесь продвижением сайта!
Конкурентов в ТОП-10 Google не нашлось.
ЗоЗПП: права потребителей Готовность: 100%
Нарушения
Не выявлены
Признаков дистанционной продажи товаров (интернет-магазина) не обнаружено — требования ЗоЗПП о раскрытии информации продавца к сайту не применяются. Нарушений нет.
ФЗ-149: рекомендательные технологии Готовность: 100%
Нарушения
Не выявлены
Рекомендательные блоки («с этим покупают», «похожие товары» и т.п.) на сайте не обнаружены — требования ст. 10.7 ФЗ-149 к сайту не применяются. Нарушений нет.
ФЗ-38: реклама Готовность: 100%
Нарушения
Не выявлены
Рекламных тематик с обязательными оговорками (медицина, БАД, кредиты и займы, новостройки) на сайте не обнаружено. Нарушений нет.
ФЗ-436: защита детей Готовность: 100%
Нарушения
Не выявлены
Признаков информационной продукции (новости, видео, книги, игры, курсы) не обнаружено — обязательная возрастная маркировка по ФЗ-436 сайту не требуется. Нарушений нет.
Вердикт
Сайт spookjs.com не совсем готов к продвижению (процент готовности лишь 58%). Для попадания в ТОПы поисковых систем нужно:
Исправьте ошибки в мета-тегах.
Исправьте ошибки индексации.
Поделитесь с друзьями: