Collected research
Listen to the whispers: web timing attacks that actually work
Web timing attacks have historically been lab-bound; this research reduces the reliably exploitable differential to roughly 200 microseconds and validates its techniques against a test bed of 30,000 live sites. It shows timing alone can reveal hidden attack surface such as unlinked parameters and routes, confirm blind server-side injection into SQL, JSON and parameter-parsing sinks, and expose reverse-proxy misconfiguration including scoped SSRF and front-end rule bypass.
Record
- Researcher
- James Kettle
- Published by
- PortSwigger Research
- Date
- Topic
- Other
In the archive
Related sources
- Timeless Timing Attacks: Exploiting Concurrency to Leak Secrets over Remote Connections
- h2spacex implementation
- Param Miner timing-attack implementation
- nowafpls WAF bypass implementation
- DEF CON 32 - Listen to the Whispers: Web Timing Attacks that Actually Work - James Kettle
- Listen to the Whispers: Web Timing Attacks that Actually Work
Tags
This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .