6 ms·
A timing attack with CSS selectors and JavaScript
- driverdan 8y agoI don't understand the point of this. What elements will a timing attack work against that you can't read the value from directly? I didn't notice any discussion of this in the article. Edit: I see how this works. It will allow you to exfiltrate data from 3rd party websites that pass the URL hash into jQuery. An interesting idea but limited in scope.
- deleted 8y ago[deleted]
- Novashi 8y agoI still don't get it. How are you getting a successful request and a page render for the 3rd party site, but not able to query the 3rd party DOM? If you phished someone, there's probably better things you can do to lead to a fuller compromise.
- shawnz 8y agoIt's described right in the article: embed the victim page in an iframe. Because of the same-origin policy you shouldn't be able to access its DOM, but with this trick, you can.
- EastSmith 8y agoCool hack. May be it is time for browsers to disable iframes by default and ask the end user if they want to run them via the standard browser confirmation mechanisms site by site.
- nerdponx 8y agoThere are so many individual pieces of HTML and JS that I wish I could do this with. Mostly web APIs. On a URL-by-URL basis.
- gcb0 8y agoyou all should install uMatrix webextension and stop just "wishing". the future is now :)
- nerdponx 8y agoDoes uMatrix let me block specific JS web APIs and HTML elements like iframes? It never could in the past.
- clear_dg 8y agouMatrix can block frames and js requests on a domain/sub-domain level. afaik, it can't block at url level, if that's what you meant. That said, uMatrix, from what I remember, uses the webRequest api which does work from urls. So if you know JS, you can always create an extension and add your own filter.
- nerdponx 8y agoTo be clear, on the JS side I'm talking about providing whitelist-only access to things like the ambient light level, which is provided through a standardized browser API.
- gcb0 8y agoyes. I block iframes globally and the web never been better. it will show a checkered pattern with a link to open the frame in another window. so you don't even have to whitelist sites or anything. if you care about the frame, like for a embedded video, just open it on its own tab with a single click
- throwaway2016a 8y ago> Have you ever encountered a website that runs jQuery(location.hash)? No. Actually I have never seen a website do that. What sites do that? What is the actual use of grabbing an element that has an ID that matches the URL hash? And this attack will only work on those sites. This is just one more variation of the best practice: don't trust user/client supplied data. Edit: Though academically I actually find how this was implemented to be really interesting. I'm just not sure what uses it would have in the wild.
- dan-robertson 8y ago> What is the actual use of grabbing an element that has an ID that matches the URL hash Well normally when you load such a page the browser will scroll down to that element. Perhaps this JavaScript wants to do something like highlight the section or extract the heading to send to some analytics?
- Guest9812398 8y agoI use it for linking to comments on my site. Users can copy a link to a particular comment, and the link directs people to the appropriate topic and location on the page. I'm assuming that using X-Frame-Options to prevent the page from appearing in a frame prevents this type of attack.
- masklinn 8y ago> I use it for linking to comments on my site. Users can copy a link to a particular comment, and the link directs people to the appropriate topic and location on the page. That works out of the box, it's a native HTML/browser feature. Why do you pass location.hash to jQuery?
- Guest9812398 8y agoOh, my mistake, it's been a while since I wrote the code. I use it to style the linked comment. So, the browser automatically scrolls to the appropriate location, and then jQuery adds a style to that comment so the user can easily locate it, or refind it if they scroll up and down the page.
- detaro 8y agoI would have thought Chrome's site isolation would prevent this. Not enabled in the author's chromium build, or not helping for some reason?
- pygy_ 8y agoChrome isolation is partial. Several unrelated tabs can share the same process.
- deleted 8y ago[deleted]
- gsnedders 8y ago"Site Isolation" is the name of a specific feature. As of Chrome 67, Site Isolation is enabled by default on desktop, so only tabs from the same (scheme, eTLD+1) can share processes, and cross-origin iframes are moved out-of-process based on the same rule. See https://security.googleblog.com/2018/07/mitigating-spectre-with-site-isolation.html https://security.googleblog.com/2018/07/mitigating-spectre-w...
- deleted 8y ago[deleted]
- SimeVidas 8y agoWhy does the RSS link on that website link to feedly.com instead of the feed directly? Weird.
- dotancohen 8y agoMetrics collection.
- otriv 8y agoThis is a good time to shill NoScript. If your browser runs JavaScript automatically, then you are putting your privacy and safety at risk.