Collected research
CSS data exfiltration in Firefox via a single injection point
Firefox parses stylesheets synchronously and caps connections per host, which blocks the single-injection CSS exfiltration trick that works in Chrome. Splitting each @import into its own style element and serving the polling endpoints over HTTP/2 removes both limits, so a CSRF token leaks character by character from one injection point in seconds.
Record
- Researcher
- mibe
- Published by
- research.securitum.com
- Date
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of mibe, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .