Tricky Web Timing Attacks Are Getting Easier to Use—and Abuse
ID: 4d22673b-63a6-5390-8f23-224d826b3eda
STIX ID: report--4d22673b-63a6-5390-8f23-224d826b3eda
Feed Name: WIRED Security
Threat Score
Researchers demonstrated that web timing attacks—refinements of the “timeless timing” approach over HTTP/2—are practical and can reliably leak information useful to attackers. By reducing network and server noise and validating techniques against a 30,000-site testbed, the work shows these timing methods can reveal server-side injection flaws and misconfigured reverse proxies, increasing the feasibility of exploitation across many web applications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
