Rob Auger from OWASP/WASC/CGiSecurity on Timing..
ID: 1d63725c-0abb-5ec8-9122-2a9264d87e79
STIX ID: report--1d63725c-0abb-5ec8-9122-2a9264d87e79
Feed Name: SensePost Blog
Threat Score
This mailing-list excerpt describes a timing-based CSRF technique for distributed brute-forcing of login pages, referencing research papers and diagrams that show how timing differences in a victim's browser can be used to detect successful logins and notify an attacker; the content is research/discussion-oriented rather than a report of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
