Collected research
Username Enumeration Timing Attacks (Sensepost)
extern blog SensePost;
SensePost's release post for the BlackHat/DefCon 2007 timing work: the squeeza SQL injection tool, which splits exploit from payload and exfiltrates over error messages, DNS or response timing against MS-SQL. It also introduces Cross Site Request Timing, timing cross-domain page loads to defeat the same-origin policy and brute-force a time-leaky login page from a popular page's visitors.
Record
- Document
- extern blog SensePost;
- Researcher
- haroon
- Published by
- sensepost.com
- Topic
- Other
In the archive
Related sources
- Squeeza and Cross-Site Request Timing Whitepaper
- Squeeza and Cross-Site Request Timing Whitepaper
- Squeeza
Tags
This page is the archive's own catalogue record. The research is the work of haroon, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .