Collected research
Scriptless Attacks: Stealing the Pie Without Touching the Sill
A CCS 2012 paper asking what an attacker can still steal once JavaScript is blocked by CSP, NoScript or sandboxed iframes. It builds side channels from CSS, inactive SVG images and crafted attack fonts to measure and exfiltrate displayed data, and adds a browser patch letting a page tell it was loaded in a detached view or pop-up.
Record
- Researcher
- Mario Heiderich, Marcus Niemietz, Felix Schuster, Thorsten Holz and Jörg Schwenk
- Published by
- nds.rub.de
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mario Heiderich, Marcus Niemietz, Felix Schuster, Thorsten Holz and Jörg Schwenk, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .