Web Hack List

Other nomination

Performing DDoS attacks with HTML5 Cross Origin Requests & WebWorkers

A WebWorker firing cross-origin GET requests pushes more than 10,000 requests a minute from one Chrome or Safari tab, because CORS only restricts reading the response, not sending it. A changing dummy query parameter defeats the browser's refusal to repeat requests to a URL that returned no Access-Control-Allow-Origin header.

Record

Researcher
lava

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of lava, first published at the original source. Preserved copies are kept so the citation survives its host.