Web Hack List

Collected research

Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks

[1908.02204] Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks

A cross-origin state inference attack lures a victim to an attacker page that uses cross-origin browser behaviour, or XS-Leaks, to infer the victim's state at a target site, going well past logged-in detection to deanonymise account owners and tell account types apart. The work generalises 40 attack classes, finds a new postMessage-based leak, and its tool finds attacks on 58 popular sites.

Record

Document
[1908.02204] Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks
Researcher
Avinash Sudhodanan, Soheil Khodayari and Juan Caballero
Published by
arXiv.org
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Avinash Sudhodanan, Soheil Khodayari and Juan Caballero, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .