Web Hack List

Other nomination

Slideshare

Grossman and Johansen show that buying ordinary display-ad impressions is enough to run JavaScript in a million browsers at once. The ad-delivered code performs CSRF, login detection, intranet probing, distributed hash cracking and application-level DDoS, bypassing the six-connections-per-host limit with image loops. They tested it live for cents per thousand impressions.

Record

Researcher
Jeremiah Grossman and Matt Johansen
Published by
slideshare.net
Format
Slides

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman and Matt Johansen, first published at the original source. Preserved copies are kept so the citation survives its host.