Web Hack List

Top 10 Web Hacking Techniques

2013

The 2013 Top 10 Web Hacking Techniques: all 10 winners and 53 nominated and collected techniques, each with its researcher, summary and preserved source.

53 records · 10 in the top ten · open this year in the interactive archive

The top ten

  1. #1 Mario Heiderich -- Mutation XSS Mario Heiderich, Jörg Schwenk, Tilman Frosch, Jonas Magazinius and Edward Z. Yang

    Reading innerHTML makes browsers rewrite markup, so a string that passes every server- and client-side XSS filter can be mutated into a live vector. Seven mutations are named - backticks as attribute delimiters, XML…

  2. #2 Angelo Prado, Neal Harris, Yoel Gluck -- BREACH Michael Mimoso

    Report on BREACH, presented at Black Hat USA 2013 by Angelo Prado, Neal Harris and Yoel Gluck. Where CRIME attacked TLS compression, BREACH attacks HTTP-level gzip: the attacker reflects guessed characters into a…

  3. #3 Pixel Perfect Timing Attacks with HTML5 Paul Stone

    Paul Stone demonstrates browser timing attacks using SVG filters to recover pixels and distinguish visited links. The OCR proof of concept recognises hexadecimal text by sampling four distinct pixels per character, with…

  4. #4 Lucky 13 Attack Nadhem AlFardan and Kenny Paterson

    TLS and DTLS CBC decryption runs measurably faster when a record carries at least two bytes of valid padding, because the 13-byte MAC header aligns hash compression blocks differently. Timing TLS error messages on a LAN…

  5. #5 Weaknesses in RC4 Nadhem AlFardan, Dan Bernstein, Kenny Paterson, Bertram Poettering and Jacob Schuldt

    Measured the keystream biases of RC4 as used in TLS and turned them into plaintext recovery. A single-byte-bias attack over the first 256 keystream bytes recovers 220 bytes of a repeated plaintext from roughly 2^30…

  6. #6 Timur Yunusov and Alexey Osipov -- XML Out of Band Data Retrieval Timur Yunusov and Alexey Osipov

    A Black Hat EU talk on pulling data out of XML parsers that return neither errors nor document output. Nested parameter entities loaded from an attacker-controlled external DTD smuggle file contents into a URL, and…

  7. #7 Million Browser Botnet Jeremiah Grossman and Matt Johansen

    Grossman and Johansen show ad networks will run arbitrary attacker JavaScript, so a $0.15 CPM buy rents a million browsers with no exploit or malware. The rented browsers do CSRF, login detection, deanonymisation…

  8. #8 Large Scale Detection of DOM based XSS Sebastian Lekies, Ben Stock and Martin Johns

    Chromium's V8 engine and its WebKit DOM were patched to track taint byte by byte, so every character arriving at a sink carried its source and any encoding applied. Knowing the exact syntactic context let the tool build…

  9. #9 Tor Hidden-Service Passive De-Cloaking Robert Hansen

    A passive method for locating the real host of a Tor hidden service: bots on Tor poll the service while a feed of Internet outages is watched, and when every bot loses it at the moment of a known network break, the…

  10. #10 HTML5 Hard Disk Filler™ API Feross Aboukhadijeh

    The Web Storage spec asks browsers to stop affiliated sites pooling localStorage quota, but Chrome, Safari and IE enforced the limit strictly per origin. Writing from many subdomains of one domain therefore gave a page…

Also collected