Web Hack List

Collected research

Username Enumeration Timing Attacks (Sensepost)

extern blog SensePost;

SensePost's release post for the BlackHat/DefCon 2007 timing work: the squeeza SQL injection tool, which splits exploit from payload and exfiltrates over error messages, DNS or response timing against MS-SQL. It also introduces Cross Site Request Timing, timing cross-domain page loads to defeat the same-origin policy and brute-force a time-leaky login page from a popular page's visitors.

Record

Document
extern blog SensePost;
Researcher
haroon
Published by
sensepost.com
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of haroon, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .