New SnailLoad Attack Exploits Network Latency to Spy on Users' Web Activities
ID: 2c1560a9-5573-58d4-8373-68b8c4d7f5ef
STIX ID: report--2c1560a9-5573-58d4-8373-68b8c4d7f5ef
Feed Name: The Hacker News
Researchers at Graz University of Technology disclosed "SnailLoad", a network-latency side-channel that remotely fingerprints user web/video activity by inducing a victim to load a slow resource from an attacker-controlled server and measuring RTT traces, with reported classification accuracies up to 98% for videos and 63% for websites; the root cause is bufferbloat in the last transport node. The report also highlights a separate NAT handling weakness in many routers that can allow attackers on the same Wi‑Fi to forge TCP RSTs to clear NAT mappings, potentially enabling TCP hijacking, page poisoning, or DoS, and notes vendors and OpenWrt are preparing patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
