Web Hack List

Collected research

Scriptless Attacks: Stealing the Pie Without Touching the Sill

A CCS 2012 paper asking what an attacker can still steal once JavaScript is blocked by CSP, NoScript or sandboxed iframes. It builds side channels from CSS, inactive SVG images and crafted attack fonts to measure and exfiltrate displayed data, and adds a browser patch letting a page tell it was loaded in a detached view or pop-up.

Record

Researcher
Mario Heiderich, Marcus Niemietz, Felix Schuster, Thorsten Holz and Jörg Schwenk
Published by
nds.rub.de
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mario Heiderich, Marcus Niemietz, Felix Schuster, Thorsten Holz and Jörg Schwenk, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .