TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Matryoshka: Wrapping Overflow Leak on Frames

63 pointsby sirdarckcatover 11 years ago

4 comments

mcphilipover 11 years ago
Fascinating.<p>Is it correct to say that extracting information about the text in a target iframe using this attack depends on knowing the pixel widths of all the characters in the font used in an arbitrary line of text in the target iframe?
评论 #6429979 未加载
guruzover 11 years ago
From the headline, i first thought about the MKV video container and video frames. :)
mylorseover 11 years ago
Good thing I do not run Javascript, esp. when items are fetched from other domains:<p><a href="http://postimg.org/image/3m9v8eyrx/" rel="nofollow">http:&#x2F;&#x2F;postimg.org&#x2F;image&#x2F;3m9v8eyrx&#x2F;</a><p>I wonder how many people are still naive, and just leave it JS on, no questions asked..
评论 #6429412 未加载
评论 #6430119 未加载
rwmjover 11 years ago
Could the browser make small fractional random changes (+&#x2F;-1 px) to the requested iframe size to avoid this attack?