logo

Rob Auger from OWASP/WASC/CGiSecurity on Timing..

ID: 1d63725c-0abb-5ec8-9122-2a9264d87e79

STIX ID: report--1d63725c-0abb-5ec8-9122-2a9264d87e79

Feed Name: SensePost Blog

Threat Score
30/100

Date Published: 2007-12-11

Date Updated: 2026-04-29

...
...

This mailing-list excerpt describes a timing-based CSRF technique for distributed brute-forcing of login pages, referencing research papers and diagrams that show how timing differences in a victim's browser can be used to detect successful logins and notify an attacker; the content is research/discussion-oriented rather than a report of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.