Web Hack List

Collected research

HEIST: HTTP Encrypted Information can be Stolen Through TCP-Windows

Browser timing APIs expose when a response arrives relative to TCP window boundaries, letting a malicious page measure the exact byte length of any cross-origin HTTPS response. Because TLS does not hide length, compression oracles like CRIME and BREACH become exploitable from JavaScript alone with no man-in-the-middle position, and HTTP/2 makes the attack stronger still.

Record

Researcher
Mathy Vanhoef and Tom Van Goethem
Published by
blackhat.com
Format
Whitepaper
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Mathy Vanhoef and Tom Van Goethem, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .