Web Hack List

Collected research

Timing Attacks Have Never Been So Practical: Advanced Cross-Site Search Attacks

Cross-site search asks a victim's logged-in service a boolean question with a cross-origin request and reads the answer from response time, since the same-origin policy hides the body. Where a reflected parameter inflates the response it is easy; otherwise the browser-based variant caches responses once and re-times them from cache, and second-order attacks plant match-all and inflating records so the empty answer becomes the larger one. Gmail names and card digits recovered.

Record

Researcher
Nethanel Gelernter
Published by
blackhat.com
Format
Whitepaper
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Nethanel Gelernter, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .