Web Hack List

Later archive addition

Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks

The paper systematizes Cross-Origin State Inference attacks into 40 XS-Leak classes and introduces a postMessage-based leak. Its Basta-COSI tool combines multiple vectors across browsers to distinguish user states, finding login, ownership, account-type, SSO, or access leaks in all 62 tested applications and sites.

Record

Researcher
Avinash Sudhodanan, Soheil Khodayari and Juan Caballero
Published by
arXiv.org

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Avinash Sudhodanan, Soheil Khodayari and Juan Caballero, first published at the original source. Preserved copies are kept so the citation survives its host.