Web Hack List

Other nomination

Username Enumeration Timing Attacks (Sensepost)

SensePost's release post for the BlackHat/DefCon 2007 timing work: the squeeza SQL injection tool, which splits exploit from payload and exfiltrates over error messages, DNS or response timing against MS-SQL. It also introduces Cross Site Request Timing, timing cross-domain page loads to defeat the same-origin policy and brute-force a time-leaky login page from a popular page's visitors.

Record

Researcher
haroon

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of haroon, first published at the original source. Preserved copies are kept so the citation survives its host.