Top 10 winner
XSS-Leak: Leaking Cross-Origin Redirects
Chrome schedules equal-priority pending requests by port, then scheme, then host, so with the socket pool exhausted an attacker can race their own request against a victim page's cross-origin request and learn whether their hostname sorts before or after the target's. Binary searching that oracle leaks the subdomain of a cross-origin fetch or where a redirect lands.
Record
- Researcher
- Salvatore Abello and @salvatoreabello
- Published by
- Salvatore Abello's Blog
- Date
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Salvatore Abello and @salvatoreabello, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .