TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

A timing attack with CSS selectors and JavaScript

104 点作者 mhasbini超过 6 年前

6 条评论

throwaway2016a超过 6 年前
&gt; Have you ever encountered a website that runs jQuery(location.hash)?<p>No. Actually I have never seen a website do that. What sites do that? What is the actual use of grabbing an element that has an ID that matches the URL hash?<p>And this attack will only work on those sites.<p>This is just one more variation of the best practice: don&#x27;t trust user&#x2F;client supplied data.<p>Edit: Though academically I actually find how this was implemented to be really interesting. I&#x27;m just not sure what uses it would have in the wild.
评论 #18160508 未加载
评论 #18160557 未加载
评论 #18160718 未加载
评论 #18160722 未加载
评论 #18160802 未加载
driverdan超过 6 年前
I don&#x27;t understand the point of this. What elements will a timing attack work against that you can&#x27;t read the value from directly? I didn&#x27;t notice any discussion of this in the article.<p>Edit: I see how this works. It will allow you to exfiltrate data from 3rd party websites that pass the URL hash into jQuery. An interesting idea but limited in scope.
评论 #18161394 未加载
评论 #18160391 未加载
EastSmith超过 6 年前
Cool hack.<p>May be it is time for browsers to disable iframes by default and ask the end user if they want to run them via the standard browser confirmation mechanisms site by site.
评论 #18160988 未加载
评论 #18160888 未加载
评论 #18160567 未加载
detaro超过 6 年前
I would have thought Chrome&#x27;s site isolation would prevent this. Not enabled in the author&#x27;s chromium build, or not helping for some reason?
评论 #18161468 未加载
评论 #18160595 未加载
otriv超过 6 年前
This is a good time to shill NoScript. If your browser runs JavaScript automatically, then you are putting your privacy and safety at risk.
SimeVidas超过 6 年前
Why does the RSS link on that website link to feedly.com instead of the feed directly? Weird.
评论 #18161313 未加载