XS-Leaks steal data the same-origin policy swears it protects. SOP hides response contents, not response behavior. This issue covers error-event oracles, frame counting via window.length, the single global socket pool that turns any browser into a stopwatch, and cache probing (terjanq leaked private Google emails this way). Blind injection, cross-origin, against a site you cannot read. https://www.kayssel.com/newsletter/issue-62/
#InfoSec #CyberSecurity #WebSecurity #BugBounty #AppSec #XSLeaks
#xsleaks
1 posts · Last used Aug 09
You've seen all posts
