Collected research
A timing attack with CSS selectors and Javascript
A page that passes location.hash to jQuery lets an attacker choose the CSS selector it evaluates. Deliberately expensive pseudo-class chains plus right-to-left short-circuiting make matching slow only when a guessed attribute prefix is correct, and because both pages share one thread the attacker frame times the delay and binary-searches a CSRF token out character by character.
Record
- Researcher
- Sigurd Kolltveit
- Published by
- sheddow's blog
- Date
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sigurd Kolltveit, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .