Web Hack List

Top 10 winner

Cross-domain search timing

Demonstrates cross-domain data theft using only request timing. An attacker page loads a victim's search URL and times img onerror/onload or an iframe onload, giving a one-bit fast/slow oracle. Against Yahoo! Mail this reveals login state and, because indexed terms answer slower than unindexed ones, answers yes/no questions about inbox contents.

Record

Researcher
Chris Evans
Published by
scarybeastsecurity.blogspot.com
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .