Web Hack List

Collected research

Performing DDoS attacks with HTML5 Cross Origin Requests & WebWorkers

A WebWorker firing cross-origin GET requests pushes more than 10,000 requests a minute from one Chrome or Safari tab, because CORS only restricts reading the response, not sending it. A changing dummy query parameter defeats the browser's refusal to repeat requests to a URL that returned no Access-Control-Allow-Origin header.

Record

Researcher
lava
Published by
blog.andlabs.org
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of lava, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .