Top 10 winner
Cross-domain search timing
Demonstrates cross-domain data theft using only request timing. An attacker page loads a victim's search URL and times img onerror/onload or an iframe onload, giving a one-bit fast/slow oracle. Against Yahoo! Mail this reveals login state and, because indexed terms answer slower than unindexed ones, answers yes/no questions about inbox contents.
Record
- Researcher
- Chris Evans
- Published by
- scarybeastsecurity.blogspot.com
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .