Collected research
Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks
[1908.02204] Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks
A cross-origin state inference attack lures a victim to an attacker page that uses cross-origin browser behaviour, or XS-Leaks, to infer the victim's state at a target site, going well past logged-in detection to deanonymise account owners and tell account types apart. The work generalises 40 attack classes, finds a new postMessage-based leak, and its tool finds attacks on 58 popular sites.
Record
- Document
- [1908.02204] Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks
- Researcher
- Avinash Sudhodanan, Soheil Khodayari and Juan Caballero
- Published by
- arXiv.org
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Avinash Sudhodanan, Soheil Khodayari and Juan Caballero, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .