Web Hack List

Top 10 winner

XSS-Leak: Leaking Cross-Origin Redirects

Chrome schedules equal-priority pending requests by port, then scheme, then host, so with the socket pool exhausted an attacker can race their own request against a victim page's cross-origin request and learn whether their hostname sorts before or after the target's. Binary searching that oracle leaks the subdomain of a cross-origin fetch or where a redirect lands.

Record

Researcher
Salvatore Abello and @salvatoreabello
Published by
Salvatore Abello's Blog
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Salvatore Abello and @salvatoreabello, first published at the original source. Preserved copies are kept so the citation survives its host.