Web Hack List

Top 10 winner

XS-Searching Google's bug tracker to find out vulnerable source code

XS-Searching Google’s bug tracker to find out vulnerable source code

Monorail's CSV export lacked CSRF protection and allowed a column to be repeated, so a search that matched a bug returned a hugely inflated file. Timing how long that response takes to enter the Cache API answers cross-origin yes/no questions, and binary search over Chromium's public directory tree leaks paths and line numbers named in private security bugs.

Record

Document
XS-Searching Google’s bug tracker to find out vulnerable source code
Researcher
Luan Herrera and @lbherrera_
Published by
Medium
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Luan Herrera and @lbherrera_, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .