Web Hack List

Collected research

CSS data exfiltration in Firefox via a single injection point

Firefox parses stylesheets synchronously and caps connections per host, which blocks the single-injection CSS exfiltration trick that works in Chrome. Splitting each @import into its own style element and serving the polling endpoints over HTTP/2 removes both limits, so a CSRF token leaks character by character from one injection point in seconds.

Record

Researcher
mibe
Published by
research.securitum.com
Date
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of mibe, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .